etcd Cross-site Request Forgery (CSRF)
Modified: 11/8/2023
package
pkg:go/go.etcd.io/etcd/v3
etcd Cross-site Request Forgery (CSRF)
Modified: 11/8/2023
etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
Modified: 9/10/2026
Etcd-io Improper Authentication vulnerability
Modified: 12/6/2023
go.etcd.io/etcd Authentication Bypass
Modified: 9/10/2026
etcd vulnerable to TOCTOU of gateway endpoint authentication
Modified: 10/6/2022
Etcd Gateway TLS endpoint validation only confirms TCP reachability
Modified: 9/10/2026
etcd's WAL `ReadAll` method vulnerable to an entry with large index causing panic
Modified: 9/10/2026
Etcd embed auto compaction retention negative value causing a compaction loop or a crash
Modified: 9/10/2026
etcd: Authorization bypasses in multiple APIs
Modified: 9/10/2026
etcd: Nested etcd transactions bypass RBAC authorization checks
Modified: 9/10/2026
Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only
Modified: 9/10/2026
etcd RBAC bypass allows unauthorized data access via PrevKv/lease attachment in nested transaction Put requests
Modified: 9/10/2026
etcd: Watch API authorization bypass via open-ended range requests
Modified: 9/10/2026
Etcd Gateway TLS endpoint validation only confirms TCP reachability in go.etcd.io/etcd
Modified: 2/4/2026
Etcd embed auto compaction retention negative value causing a compaction loop or a crash in go.etcd.io/etcd
Modified: 2/4/2026
Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only in go.etcd.io/etcd
Modified: 2/4/2026
Authorization bypasses in multiple APIs in go.etcd.io/etcd
Modified: 4/10/2026
Nested etcd transactions bypass RBAC authorization checks in go.etcd.io/etcd
Modified: 4/10/2026