go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.
References
| Link | Resource |
|---|---|
| https://github.com/ethereum/go-ethereum/commit/abeb78c647e354ed922726a1d719ac7bc64a07e2 | Patch |
| https://github.com/ethereum/go-ethereum/security/advisories/GHSA-mr7q-c9w9-wh4h | Third Party Advisory |
Configurations
History
29 Jan 2026, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/ethereum/go-ethereum/commit/abeb78c647e354ed922726a1d719ac7bc64a07e2 - Patch | |
| References | () https://github.com/ethereum/go-ethereum/security/advisories/GHSA-mr7q-c9w9-wh4h - Third Party Advisory | |
| First Time |
Ethereum
Ethereum go Ethereum |
13 Jan 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 21:15
Updated : 2026-01-29 18:03
NVD link : CVE-2026-22862
Mitre link : CVE-2026-22862
CVE.ORG link : CVE-2026-22862
JSON object : View
Products Affected
ethereum
- go_ethereum
CWE
CWE-20
Improper Input Validation
