PT-2026-20348 · Unknown · Go-Ethereum
Waleed Ahmed
·
Published
2026-02-17
·
Updated
2026-04-16
·
CVE-2026-26314
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
go-ethereum (geth) versions prior to 1.16.9
go-ethereum (geth) versions prior to 1.17.0
Description
A specially crafted message can cause go-ethereum (geth) nodes to crash or shut down remotely. This issue does not require authentication. The vulnerable component is the peer-to-peer message handling within the Ethereum protocol implementation.
Recommendations
Upgrade to version 1.16.9 or later.
Upgrade to version 1.17.0 or later.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Go-Ethereum