Kubernetes v1.37 promotes etcd RangeStream to beta and enables the EtcdRangeStream feature gate by default. With etcd v3.7 or later, the kube-apiserver can consume large collection reads incrementally instead of requiring both etcd and the API server to retain an entire paginated response in memory.
The streamed-read path reduces and stabilizes memory usage during large list operations, lowering the risk of out-of-memory failures in control planes managing extensive resource collections. Clusters using older etcd releases remain supported through the existing paginated Range request path; administrators can confirm RangeStream activity through the listStream etcd operation metric or disable it explicitly through the feature gate.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Kubernetes v1.37 promoted the EtcdRangeStream feature gate to beta and enabled it by default. With etcd v3.7 or later, kube-apiserver can stream large collection reads in chunks to reduce memory pressure; it falls back to paginated Range reads with older or unsupported etcd servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.