Technology

etcd

1 connections

Definition

What it is

Recent developments

Latest signals
  • [tool] Improve benchmark tool · Issue #21634 · etcd-io/etcd. Proposal to improve etcd's benchmark tool (tools/benchmark). Current limitations: lack of time-series data, no resource monitoring, no standard test profiles, manual comparison. Proposed improvements: Docker setup, time-series collection, branch/commit comparison automation, standardized profiles (ReadHeavy, etc.), visualization. Per GitHub (etcd-io/etcd) (2026-04-17).

  • etcd v3.7.0 shipped in July with RangeStream and v2store removal. The release adds the long-requested RangeStream feature, drops the legacy v2 storage backend, and bumps to bbolt v1.5.1 and raft v3.7.0; v3.4 has been end-of-life since May 15, 2026. Per Announcing etcd v3.7.0 and Announcing etcd 3.7.0-beta.0.

  • March 2026 security release patched an auth bypass reachable without credentials. CVE-2026-33413 and CVE-2026-33343 let unauthenticated callers hit the gRPC MemberList, Alarm, and Lease APIs and trigger compaction; fixed in 3.4.42, 3.5.28, and 3.6.9. Per March 20 Security Release Patches Auth Vulnerabilities.

  • A second, authenticated RBAC bypass inside transactions was patched in May. CVE-2026-44283 let authenticated users sidestep RBAC checks via PrevKv or lease attachment on Put requests nested in transactions; fixed in 3.4.44, 3.5.30, 3.6.11. Tertiary sourcing only. Per CVE-2026-44283 etcd Auth Bypass: Patch Versions and Verify Transaction RBAC.

  • July's patch release fixed a websocket auth bug tied to bearer-prefixed tokens. v3.5.32 and v3.6.13 also close dependency CVEs and add an opt-in flag to deprecate v2 storage ahead of the 3.7 removal. Per etcd July Patch Releases: v3.5.32 and v3.6.13. Sources: GitHub (etcd-io/etcd)

Connections 1

Outbound 1