Vulnerability Report: GO-2026-4923
- CVE-2026-33817
- Affects: go.etcd.io/bbolt
- Published: Apr 06, 2026
Index out-of-range when encountering a branch page with zero elements in go.etcd.io/bbolt
Affected Packages
-
PathVersionsSymbols
-
all versions, no known fixed
43 affected symbols
- Bucket.CreateBucket
- Bucket.CreateBucketIfNotExists
- Bucket.Delete
- Bucket.DeleteBucket
- Bucket.ForEach
- Bucket.ForEachBucket
- Bucket.MoveBucket
- Bucket.NextSequence
- Bucket.Put
- Bucket.SetSequence
- Bucket.Stats
- Compact
- Cursor.Delete
- DB.Batch
- DB.Begin
- DB.Close
- DB.Sync
- DB.Update
- DB.View
- DefaultLogger.Debug
- DefaultLogger.Debugf
- DefaultLogger.Error
- DefaultLogger.Errorf
- DefaultLogger.Fatal
- DefaultLogger.Fatalf
- DefaultLogger.Info
- DefaultLogger.Infof
- DefaultLogger.Panic
- DefaultLogger.Panicf
- DefaultLogger.Warning
- DefaultLogger.Warningf
- Open
- Tx.Check
- Tx.Commit
- Tx.Copy
- Tx.CopyFile
- Tx.CreateBucket
- Tx.CreateBucketIfNotExists
- Tx.DeleteBucket
- Tx.ForEach
- Tx.MoveBucket
- Tx.Rollback
- Tx.WriteTo
Aliases
References
- https://github.com/etcd-io/bbolt/pull/1171/changes/386d5b69785937d1aa20cb25c8439404cf398143
- https://github.com/golang/vulndb/issues/4923
- https://vuln.go.dev/ID/GO-2026-4923.json
Credits
- Quoc Bui (github.com/quocvibui)
Feedback
See anything missing or incorrect?
Suggest an edit to this report.