CVE-2026-73500
CVE-2026-73500: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-73500] Denial of Service via unbounded TLS handshake goroutines
CVE-2026-73500Source published Source updated
etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go, each connection handled by tlsListener.acceptLoop spawns a goroutine that blocks indefinitely inside tls. Conn.Handshake() and remains tracked in the pending map. Unbounded goroutine and map growth can exhaust memory in the etcd process, causing loss of availability for the cluster and, when etcd backs Kubernetes, the control plane. This issue is fixed in versions 3.5.33, 3.6.14, and 3.7.1. A remote attacker can exploit this by opening numerous TCP connections to an etcd TLS listener without completing the TLS…
- Affected products in this advisory
- Red Hat Hardened Images
- cert-manager Operator for Red Hat OpenShift
- ExternalDNS Operator
- Multicluster Engine for Kubernetes
12 more entries in the full advisory.
- Source-reported affected versions
- < 3.5.33
- < 3.6.14
- < 3.7.1
- Source-reported fixed versions
- 3.5.33
- 3.6.14
- 3.7.1
- etcd-main-3.7.1-0.1.hum1
1 more entries in the full advisory.
- Mitigation guidance
- Restrict network access to the etcd TLS listener to only trusted clients and networks. Configure firewall rules to limit inbound connections to the etcd client port (default 2379) and peer port (default 2380) to authorized hosts. This reduces the attack surface by preventing untrusted network attackers from reaching the vulnerable service.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.