github.com/ethereum/go-ethereum
Go implementation of the Ethereum protocol
Activity
- Latest release
- 1mo ago
- Total releases
- 66
- Cadence
- ~38 days
- Last 12 months
- 11
Reach
- Stars
- 51.3k
Details
- First release
- Aug 21, 2014
| Version | Released | |
|---|---|---|
v1.17.5
patch
|
v1.17.5
patch
Dependencies (79)
+ 71 more |
|
v1.17.4
patch
|
v1.17.4
patch
Dependencies (79)
+ 71 more |
|
v1.17.3
patch
|
v1.17.3
patch
Dependencies (78)
+ 70 more |
|
v1.17.2
patch
|
v1.17.2
patch
Dependencies (77)
+ 69 more |
|
v1.17.1
patch
|
v1.17.1
patch
Dependencies (77)
+ 69 more |
|
v1.17.0
minor
|
v1.17.0
minor
Dependencies (77)
+ 69 more |
|
v1.16.9
patch
1 CVE
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev |
v1.16.9
patch
Dependencies (73)
+ 65 more |
|
v1.16.8
patch
3 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev |
v1.16.8
patch
Dependencies (73)
+ 65 more |
|
v1.16.7
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.7
patch
Dependencies (73)
+ 65 more |
|
v1.16.6
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.6
patch
Dependencies (73)
+ 65 more |
|
v1.16.5
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.5
patch
Dependencies (72)
+ 64 more |
|
v1.16.4
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.4
patch
Dependencies (72)
+ 64 more |
|
v1.16.3
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.3
patch
Dependencies (72)
+ 64 more |
|
v1.16.2
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.2
patch
Dependencies (71)
+ 63 more |
|
v1.16.1
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.1
patch
Dependencies (71)
+ 63 more |
|
v1.16.0
minor
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (71)
+ 63 more |
|
v1.15.11
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.11
patch
Dependencies (72)
+ 64 more |
|
v1.15.10
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.10
patch
Dependencies (71)
+ 63 more |
|
v1.15.9
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.9
patch
Dependencies (71)
+ 63 more |
|
v1.15.8
patch
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.8
patch
Dependencies (71)
+ 63 more |
|
v1.15.0
minor
5 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.0
minor
Dependencies (70)
+ 62 more |
|
v1.14.2
minor
6 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-24883
GO-2025-3436
GHSA-q26p-9cq4-7fc2
Feb 04, 2025
Go Ethereum vulnerable to DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum vulnerable to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.14.13
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.14.2
minor
Dependencies (72)
+ 64 more |
|
v1.13.10
patch
6 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev |
v1.13.10
patch
Dependencies (68)
+ 60 more |
|
v1.13.8
patch
6 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev |
v1.13.8
patch
Dependencies (68)
+ 60 more |
|
v1.13.7
patch
6 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev |
v1.13.7
patch
Dependencies (68)
+ 60 more |
|
v1.13.5
patch
6 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev |
v1.13.5
patch
Dependencies (69)
+ 61 more |
|
v1.13.4
patch
7 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev |
v1.13.4
patch
Dependencies (70)
+ 62 more |
|
v1.13.0
minor
7 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev |
v1.13.0
minor
Dependencies (69)
+ 61 more |
|
v1.11.5
patch
8 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev |
v1.11.5
patch
Dependencies (63)
+ 55 more |
|
v1.11.1
minor
8 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev |
v1.11.1
minor
Dependencies (63)
+ 55 more |
|
v1.10.22
patch
8 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev |
v1.10.22
patch
Dependencies (62)
+ 54 more |
|
v1.10.21
patch
9 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.21
patch
Dependencies (62)
+ 54 more |
|
v1.10.19
patch
9 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.19
patch
Dependencies (62)
+ 54 more |
|
v1.10.17
patch
9 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.17
patch
Dependencies (59)
+ 51 more |
|
v1.10.14
patch
11 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.14
patch
Dependencies (57)
+ 49 more |
|
v1.10.13
patch
11 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.13
patch
Dependencies (57)
+ 49 more |
|
v1.10.6
patch
16 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.6
patch
Dependencies (55)
+ 47 more |
|
v1.10.5
patch
16 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.5
patch
Dependencies (55)
+ 47 more |
|
v1.10.3
minor
16 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev |
v1.10.3
minor
Dependencies (55)
+ 47 more |
|
v1.9.25
patch
16 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev |
v1.9.25
patch
Dependencies (53)
+ 45 more |
|
v1.9.16
patch
22 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26241
GO-2022-0771
GHSA-69v6-xc2j-r2jf
Aug 21, 2024
Shallow copy bug in geth in github.com/ethereum/go-ethereum Shallow copy bug in geth in github.com/ethereum/go-ethereum Fixed in
1.9.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26265
GO-2021-0105
GHSA-xw37-57qp-9mm4
Jul 28, 2021
Consensus flaw in github.com/ethereum/go-ethereum Due to an incorrect state calculation, a specific set of transactions could cause a consensus disagreement, causing users of this package to reject a canonical chain. Fixed in
1.9.20
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-26242
GHSA-jm5c-rv3w-w83m
GO-2021-0103
Jun 29, 2021
Denial of service in geth
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactDenial-of-service (crash) during block processing DetailsAffected versions suffer from a vulnerability which can be exploited through the
and https://github.com/holiman/uint256/blob/4ce82e695c10ddad57215bdbeafb68b8c5df2c30/uint256.go#L451 will try to access index The The issue was brought to our attention through a bug report, showing a It was estimated that the least obvious way to fix this would be to merge the fix into
PatchesUpgrade to v1.9.18 or higher WorkaroundsNot at this time Referenceshttps://blog.ethereum.org/2020/11/12/geth_security_release/ For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.18
References
Updated Jul 08, 2026 · Source: OSV.dev |
v1.9.16
patch
Dependencies (51)
+ 43 more |
|
v1.9.14
patch
21 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26241
GO-2022-0771
GHSA-69v6-xc2j-r2jf
Aug 21, 2024
Shallow copy bug in geth in github.com/ethereum/go-ethereum Shallow copy bug in geth in github.com/ethereum/go-ethereum Fixed in
1.9.17
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26265
GO-2021-0105
GHSA-xw37-57qp-9mm4
Jul 28, 2021
Consensus flaw in github.com/ethereum/go-ethereum Due to an incorrect state calculation, a specific set of transactions could cause a consensus disagreement, causing users of this package to reject a canonical chain. Fixed in
1.9.20
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.9.14
patch
Dependencies (50)
+ 42 more |
|
v1.9.5
patch
20 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26265
GO-2021-0105
GHSA-xw37-57qp-9mm4
Jul 28, 2021
Consensus flaw in github.com/ethereum/go-ethereum Due to an incorrect state calculation, a specific set of transactions could cause a consensus disagreement, causing users of this package to reject a canonical chain. Fixed in
1.9.20
References Updated May 20, 2024 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.9.5
patch
|
|
v1.9.2
minor
19 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.9.2
minor
|
|
v0.4.2
initial
22 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-16733
GO-2022-0871
GHSA-qr2j-wrhx-4829
Aug 21, 2024
Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-19184
GO-2022-0814
GHSA-9h4h-8w5p-f28w
Aug 21, 2024
Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-12018
GHSA-p5gc-957x-gfw9
GO-2021-0075
May 14, 2022
Go Ethereum LES protocol implementation vulnerable to Denial of Service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue. Specific Go Packages Affectedgithub.com/ethereum/go-ethereum/les Fixed in
1.8.11
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.4.2
initial
|
|
v1.8.24
patch
19 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.24
patch
|
|
v1.8.22
patch
19 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.22
patch
|
|
v1.8.4
patch
22 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-16733
GO-2022-0871
GHSA-qr2j-wrhx-4829
Aug 21, 2024
Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-19184
GO-2022-0814
GHSA-9h4h-8w5p-f28w
Aug 21, 2024
Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-12018
GHSA-p5gc-957x-gfw9
GO-2021-0075
May 14, 2022
Go Ethereum LES protocol implementation vulnerable to Denial of Service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue. Specific Go Packages Affectedgithub.com/ethereum/go-ethereum/les Fixed in
1.8.11
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.4
patch
|
|
v1.8.1
minor
22 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-16733
GO-2022-0871
GHSA-qr2j-wrhx-4829
Aug 21, 2024
Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-19184
GO-2022-0814
GHSA-9h4h-8w5p-f28w
Aug 21, 2024
Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-12018
GHSA-p5gc-957x-gfw9
GO-2021-0075
May 14, 2022
Go Ethereum LES protocol implementation vulnerable to Denial of Service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue. Specific Go Packages Affectedgithub.com/ethereum/go-ethereum/les Fixed in
1.8.11
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.8.1
minor
|
|
v1.6.7
patch
22 CVEs
CVE-2026-26314
GO-2026-4507
GHSA-2gjw-fg97-vg3r
Feb 24, 2026
Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by crash via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26315
GO-2026-4511
GHSA-m6j8-rg6r-7mv8
Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum Fixed in
1.16.9
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-26313
GO-2026-4508
GHSA-689v-6xwf-5jf3
Feb 24, 2026
Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Go Ethereum affected by DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.17.0
References Updated Feb 24, 2026 · Source: OSV.dev
CVE-2026-22862
GO-2026-4315
GHSA-mr7q-c9w9-wh4h
Jan 23, 2026
DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum DoS via malicious p2p message affecting a vulnerable node in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2026-22868
GO-2026-4314
GHSA-mq3p-rrmp-79jg
Jan 23, 2026
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum Fixed in
1.16.8
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-16733
GO-2022-0871
GHSA-qr2j-wrhx-4829
Aug 21, 2024
Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Go Ethereum Improper Input Validation in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2018-19184
GO-2022-0814
GHSA-9h4h-8w5p-f28w
Aug 21, 2024
Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Go Ethereum Denial of Service in github.com/ethereum/go-ethereum Fixed in
1.8.14
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-26240
GO-2022-0775
GHSA-v592-xf75-856p
Aug 21, 2024
Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Erroneous Proof of Work calculation in geth in github.com/ethereum/go-ethereum Fixed in
1.9.24
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-29177
GO-2022-0456
GHSA-wjxw-gh3m-7pm5
Aug 21, 2024
DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum DoS via malicious p2p message in Go Ethereum in github.com/ethereum/go-ethereum Fixed in
1.10.17
References Updated Mar 03, 2026 · Source: OSV.dev
GO-2022-0392
GHSA-m6gx-rhvj-fh52
Aug 21, 2024
Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Denial of service in go-ethereum due to CVE-2020-28362 in github.com/ethereum/go-ethereum Fixed in
1.9.24
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32972
GO-2024-2819
GHSA-4xc9-8hmq-j652
May 08, 2024
Denial of Service in github.com/ethereum/go-ethereum A vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. This can result in a denial of service as the node runs out of memory. Fixed in
1.13.15
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-40591
GO-2023-2046
GHSA-ppjg-v974-84cm
Oct 25, 2023
Unbounded memory consumption in github.com/ethereum/go-ethereum Unbounded memory consumption in github.com/ethereum/go-ethereum Fixed in
1.12.1
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-42319
GHSA-v9jh-j8px-98vq
Oct 18, 2023
go-ethereum vulnerable to denial of service via crafted GraphQL query
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Geth (aka go-ethereum) through 1.13.4, when NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. References Updated Sep 13, 2024 · Source: OSV.dev
CVE-2022-37450
GHSA-rqmg-hrg4-fm69
Aug 06, 2022
Go Ethereum allows attackers to use manipulation of time-difference values to achieve replacement of main-chain blocks
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022. References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-41173
GO-2022-0256
GHSA-59hh-656j-3p7v
Jul 15, 2022
Panic via maliciously crafted message in github.com/ethereum/go-ethereum A maliciously crafted snap/1 protocol message can cause a panic. Fixed in
1.10.9
References Updated May 20, 2024 · Source: OSV.dev
CVE-2021-39137
GO-2022-0254
GHSA-9856-9gg9-qcmq
Jul 15, 2022
Consensus flaw during block processing in github.com/ethereum/go-ethereum A vulnerability in the Geth EVM can cause a node to reject the canonical chain. A memory-corruption bug within the EVM can cause a consensus error, where vulnerable nodes obtain a different stateRoot when processing a maliciously crafted transaction. This, in turn, would lead to the chain being split in two forks. Fixed in
1.10.8
References Updated May 20, 2024 · Source: OSV.dev
CVE-2018-12018
GHSA-p5gc-957x-gfw9
GO-2021-0075
May 14, 2022
Go Ethereum LES protocol implementation vulnerable to Denial of Service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue. Specific Go Packages Affectedgithub.com/ethereum/go-ethereum/les Fixed in
1.8.11
References
Updated May 20, 2024 · Source: OSV.dev
CVE-2021-42219
GHSA-vrcc-g6vj-mh5w
Mar 18, 2022
Denial of service in go-ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23327
GHSA-pvx3-gm3c-gmpr
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS). References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2022-23328
GHSA-vmf7-hmh6-vv57
Mar 05, 2022
Denial of Service in Go-Ethereum
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS). References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2021-43668
GHSA-5m8f-chrv-7rw5
Nov 23, 2021
Denial of Service in Go-Ethereum
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal. References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-26264
GHSA-r33q-22hv-j29q
GO-2021-0063
Jun 29, 2021
Denial of service in github.com/ethereum/go-ethereum
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
High
ImpactA DoS vulnerability can make a LES server crash via malicious PatchesThe vulnerability was patched in https://github.com/ethereum/go-ethereum/pull/21896. WorkaroundsThis vulnerability only concerns users explicitly enabling For more informationIf you have any questions or comments about this advisory:
Fixed in
1.9.25
References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.6.7
patch
|