← All CVEs NewScan detects
high

CVE-2026-73500

etcd 3.5.x before 3.5.33: remote denial of service on the TLS listener (CVE-2026-73500), plus CVE-2026-73499

Severity
high
Affected product
etcd
Affected versions
etcd ≥ 3.5.0, < 3.5.33
Affected versions
etcd ≥ 3.6.0, < 3.6.14
Affected versions
etcd ≥ 3.7.0, < 3.7.1
Fixed in
etcd 3.5.33
Fixed in
etcd 3.6.14
Fixed in
etcd 3.7.1
Added to NewScan
2026-08-14
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints etcd from its response and reports this CVE when the detected version falls inside the affected range below.

RECONSTRUCTED 2026-08-14: this row was an uncommitted working-tree change from the 2026-08-13 batch and a rewrite-from-HEAD during the 2026-08-14 batch clobbered it before it was ever committed or published (the 26.08.13 bundle predates it, so no copy survived). Every FIELD below - the three branch ranges, the ids, the severity, the fixed_in - is restored exactly from the D115 entry in docs/backlog.md, which records them precisely; only the original note PROSE is lost and this text replaces it. VERSION-GATED ADVISORY ONLY, and that is a policy call, not a gap: CVE-2026-73500 (8.7) is a denial of service on the TLS listener and backlog policy P1 keeps DoS out of scope as a probe, so proving it in-band would mean taking a stranger's datastore down. CVE-2026-73499 (7.1) ships in the same fix. THE VERSION ARRIVES IN-BAND, not via the tech_signatures version_from: etcd's / is a bare 404, so _fingerprint_technology never identifies it there and _resolve_versions is never reached; what does reach it is the interfaces.json /version row, whose body _probe_unauth_interfaces feeds to techdb.detect (the Langflow precedent). ONE ROW PER BRANCH because etcd shipped the fix per branch - a single lt-3.7.1 row would call a patched 3.5.33 vulnerable. Nothing is claimed about 3.4.x: no fixed release was named for that branch, and under-reporting beats a wrong claim. Measured 2026-08-13 against the purpose-built cve-class sibling pair training/cve/extra/etcd (v3.5.32 on :8137 fires, v3.5.33 on :8138 silent).

COMPONENT VERSION RANGE

NewScan fingerprints etcd from its response and reports this CVE when the detected version falls inside the affected range below.

RECONSTRUCTED 2026-08-14: this row was an uncommitted working-tree change from the 2026-08-13 batch and a rewrite-from-HEAD during the 2026-08-14 batch clobbered it before it was ever committed or published (the 26.08.13 bundle predates it, so no copy survived). Every FIELD below - the three branch ranges, the ids, the severity, the fixed_in - is restored exactly from the D115 entry in docs/backlog.md, which records them precisely; only the original note PROSE is lost and this text replaces it. VERSION-GATED ADVISORY ONLY, and that is a policy call, not a gap: CVE-2026-73500 (8.7) is a denial of service on the TLS listener and backlog policy P1 keeps DoS out of scope as a probe, so proving it in-band would mean taking a stranger's datastore down. CVE-2026-73499 (7.1) ships in the same fix. THE VERSION ARRIVES IN-BAND, not via the tech_signatures version_from: etcd's / is a bare 404, so _fingerprint_technology never identifies it there and _resolve_versions is never reached; what does reach it is the interfaces.json /version row, whose body _probe_unauth_interfaces feeds to techdb.detect (the Langflow precedent). ONE ROW PER BRANCH because etcd shipped the fix per branch - a single lt-3.7.1 row would call a patched 3.5.33 vulnerable. Nothing is claimed about 3.4.x: no fixed release was named for that branch, and under-reporting beats a wrong claim. Measured 2026-08-13 against the purpose-built cve-class sibling pair training/cve/extra/etcd (v3.5.32 on :8137 fires, v3.5.33 on :8138 silent).

COMPONENT VERSION RANGE

NewScan fingerprints etcd from its response and reports this CVE when the detected version falls inside the affected range below.

RECONSTRUCTED 2026-08-14: this row was an uncommitted working-tree change from the 2026-08-13 batch and a rewrite-from-HEAD during the 2026-08-14 batch clobbered it before it was ever committed or published (the 26.08.13 bundle predates it, so no copy survived). Every FIELD below - the three branch ranges, the ids, the severity, the fixed_in - is restored exactly from the D115 entry in docs/backlog.md, which records them precisely; only the original note PROSE is lost and this text replaces it. VERSION-GATED ADVISORY ONLY, and that is a policy call, not a gap: CVE-2026-73500 (8.7) is a denial of service on the TLS listener and backlog policy P1 keeps DoS out of scope as a probe, so proving it in-band would mean taking a stranger's datastore down. CVE-2026-73499 (7.1) ships in the same fix. THE VERSION ARRIVES IN-BAND, not via the tech_signatures version_from: etcd's / is a bare 404, so _fingerprint_technology never identifies it there and _resolve_versions is never reached; what does reach it is the interfaces.json /version row, whose body _probe_unauth_interfaces feeds to techdb.detect (the Langflow precedent). ONE ROW PER BRANCH because etcd shipped the fix per branch - a single lt-3.7.1 row would call a patched 3.5.33 vulnerable. Nothing is claimed about 3.4.x: no fixed release was named for that branch, and under-reporting beats a wrong claim. Measured 2026-08-13 against the purpose-built cve-class sibling pair training/cve/extra/etcd (v3.5.32 on :8137 fires, v3.5.33 on :8138 silent).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →