CVE-2026-59818

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List is not enforced on the gRPC listener, allowing a client with a revoked certificate to authenticate successfully over gRPC. This issue is fixed in versions 3.5.32 and 3.6.13.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:*
cpe:2.3:a:etcd:etcd:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-08 21:16

Updated : 2026-07-13 14:50


NVD link : CVE-2026-59818

Mitre link : CVE-2026-59818

CVE.ORG link : CVE-2026-59818


JSON object : View

Products Affected

etcd

  • etcd
CWE
CWE-295

Improper Certificate Validation