Etcd is a widely embedded, distributed key-value store that serves as the authoritative datastore for Kubernetes and other infrastructure platforms, giving its vulnerability footprint outsized impact despite a narrow product focus. Its recurring weakness classes—improper authentication, authorization flaws, input validation gaps, and exposure of sensitive configuration data—reflect the security-critical role the service plays in managing cluster state and access control across containerized environments. Defenders should treat etcd patch cycles as high-priority for any Kubernetes deployment and restrict network access to the service accordingly; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Etcd over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59818HIGH etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRP | Jul 8, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-33413HIGH etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, unauthorized users may bypass authentication or authorizati | Mar 26, 2026 | 8.8 | 31 | NO | NO |
CVE-2021-28235CRITICAL Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug function. | Apr 4, 2023 | 9.8 | 31 | NO | NO |
CVE-2018-16886HIGH etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is e | Jan 14, 2019 | 8.1 | 28 | NO | NO |
CVE-2020-15113HIGH In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certi | Aug 5, 2020 | 7.1 | 24 | NO | NO |
CVE-2020-15106MEDIUM In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional val | Aug 5, 2020 | 6.5 | 23 | NO | NO |
CVE-2026-33343MEDIUM etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9, an authenticated user with RBAC restricted permissions on k | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-44283MEDIUM etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease att | May 14, 2026 | 4.3 | 20 | NO | NO |
CVE-2022-34038HIGH Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: the vendor's position is that this is not a vulnerability. | Aug 22, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-32082MEDIUM etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.26 and 3.5.9, the LeaseTimeToLive API allows access to key names (not value) assoc | May 11, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Etcd.
Media articles that mention a CVE ID that affects a product developed by Etcd — matched by CVE ID, not by vendor name.