{"data":{"id":"904cb20a-5918-415f-b9ca-c9e0ca6b32b2","title":"GHSA-xg4h-6gfc-h4m8: etcd: Watch API authorization bypass via open-ended range requests","summary":"etcd (a distributed database system) has an authorization bypass vulnerability in its Watch API where users with READ permission on a single key can use `clientv3.WithFromKey()` (an open-ended request that watches from one key to the end of all stored keys) to see watch events for every key after their permitted key, not just their one allowed key. This only affects etcd clusters with authentication enabled.","solution":"Upgrade to etcd 3.7.1, etcd 3.6.14, or etcd 3.5.33. If upgrading is not immediately possible, audit all READ permission grants and revoke or restrict any you wouldn't trust with full read access, and use firewall rules or network policies to limit which hosts can connect to etcd's client port.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-xg4h-6gfc-h4m8","publishedAt":"2026-07-24T22:38:22.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":[],"issueType":"vulnerability","affectedPackages":["go.etcd.io/etcd/v3@< 3.5.33 (fixed: 3.5.33)","go.etcd.io/etcd/v3@>= 3.6.0, < 3.6.14 (fixed: 3.6.14)","go.etcd.io/etcd/v3@>= 3.7.0-alpha.0, < 3.7.1 (fixed: 3.7.1)"],"affectedVendors":[],"affectedVendorsRaw":["etcd"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-07-24T22:38:22.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}