CVE-2026-26313

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory usage by sending a specially-crafted p2p message. The issue is resolved in the v1.17.0 release.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:26

Type Values Removed Values Added
Summary
  • (es) go-ethereum (geth) es una implementación de capa de ejecución en golang del protocolo Ethereum. Antes de la versión 1.17.0, un atacante puede provocar un alto uso de memoria al enviar un mensaje p2p especialmente diseñado. El problema se resuelve en la versión 1.17.0.

23 Feb 2026, 18:41

Type Values Removed Values Added
CPE cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:*
First Time Ethereum
Ethereum go Ethereum
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/ethereum/go-ethereum/releases/tag/v1.17.0 - () https://github.com/ethereum/go-ethereum/releases/tag/v1.17.0 - Release Notes
References () https://github.com/ethereum/go-ethereum/security/advisories/GHSA-689v-6xwf-5jf3 - () https://github.com/ethereum/go-ethereum/security/advisories/GHSA-689v-6xwf-5jf3 - Vendor Advisory

19 Feb 2026, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 21:18

Updated : 2026-06-17 10:26


NVD link : CVE-2026-26313

Mitre link : CVE-2026-26313

CVE.ORG link : CVE-2026-26313


JSON object : View

Products Affected

ethereum

  • go_ethereum
CWE
CWE-770

Allocation of Resources Without Limits or Throttling