{"id":"GO-2026-6107","summary":"Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3","details":"In go.etcd.io/etcd/client/pkg/v3 before 3.5.33, 3.6.14, and 3.7.1, TLS handshakes on listeners created by NewTLSListener do not enforce a handshake deadline. An unauthenticated network attacker who connects to an etcd TLS listener without sending a ClientHello causes a goroutine and a tracking map entry to block indefinitely. Opening many such connections exhausts memory, leading to a denial of service.","aliases":["BIT-etcd-2026-73500","CVE-2026-73500","GHSA-6vch-q96h-7gc3"],"modified":"2026-08-18T17:25:39.362638606Z","published":"2026-08-18T16:38:10Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6107","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3"},{"type":"FIX","url":"https://github.com/etcd-io/etcd/pull/22130"},{"type":"WEB","url":"https://github.com/etcd-io/etcd/releases/tag/v3.5.33"},{"type":"WEB","url":"https://github.com/etcd-io/etcd/releases/tag/v3.6.14"},{"type":"WEB","url":"https://github.com/etcd-io/etcd/releases/tag/v3.7.1"}],"affected":[{"package":{"name":"go.etcd.io/etcd/client/pkg/v3","ecosystem":"Go","purl":"pkg:golang/go.etcd.io/etcd/client/pkg/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.5.33"},{"introduced":"3.6.0"},{"fixed":"3.6.14"},{"introduced":"3.7.0-alpha.0"},{"fixed":"3.7.1"}]}],"ecosystem_specific":{"imports":[{"symbols":["NewListener","NewListenerWithOpts","NewTLSListener","NewTimeoutListener","tlsListener.acceptLoop"],"path":"go.etcd.io/etcd/client/pkg/v3/transport"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6107.json"}}],"schema_version":"1.9.0","credits":[{"name":"VMware By Broadcom"}]}