Home/Product/etcd
Product

etcd

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-44283
< 3.4.44
etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability i
NONE
CVE-2026-33413
< 3.4.42
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthori
8.8HIGH
CVE-2026-33343
< 3.4.42
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authen
NONE
CVE-2022-34038
all versions
Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor'
7.5HIGH
CVE-2023-32082
< 3.4.26
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLiv
3.1LOW
CVE-2021-28235
all versions
Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function.
9.8CRITICAL
CVE-2020-15136
>= 3.3.0 and < 3.3.23
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. Wh
6.5MEDIUM
CVE-2020-15114
>= 3.3.0 and < 3.3.23
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access.
7.7HIGH
CVE-2020-15115
>= 3.3.0 and < 3.3.23
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, suc
5.8MEDIUM
CVE-2020-15113
< 3.3.23
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when pr
5.7MEDIUM
CVE-2020-15112
< 3.3.23
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll
6.5MEDIUM
CVE-2020-15106
< 3.3.23
In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in th
6.5MEDIUM
CVE-2018-16886
>= 3.2.0 and < 3.2.26
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based acces
8.1HIGH
CVE-2018-1099
<= 3.3.1
DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and t
5.5MEDIUM
CVE-2018-1098
<= 3.3.1
A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST
8.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin