CVE-2026-26314

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. The problem is resolved in the v1.16.9 and v1.17.0 releases of Geth.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:*

History

23 Feb 2026, 18:32

Type Values Removed Values Added
Summary
  • (es) go-ethereum (geth) es una implementación de capa de ejecución de golang del protocolo Ethereum. Antes de la versión 1.16.9, un nodo vulnerable puede ser forzado a apagarse/colapsar usando un mensaje especialmente diseñado. El problema está resuelto en las versiones v1.16.9 y v1.17.0 de Geth.
CPE cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:*
First Time Ethereum
Ethereum go Ethereum
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/ethereum/go-ethereum/commit/895a8597cb16c02203e38707ed2d1da5c500fe60 - () https://github.com/ethereum/go-ethereum/commit/895a8597cb16c02203e38707ed2d1da5c500fe60 - Patch
References () https://github.com/ethereum/go-ethereum/releases/tag/v1.16.9 - () https://github.com/ethereum/go-ethereum/releases/tag/v1.16.9 - Release Notes
References () https://github.com/ethereum/go-ethereum/security/advisories/GHSA-2gjw-fg97-vg3r - () https://github.com/ethereum/go-ethereum/security/advisories/GHSA-2gjw-fg97-vg3r - Vendor Advisory

19 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 22:16

Updated : 2026-02-23 18:32


NVD link : CVE-2026-26314

Mitre link : CVE-2026-26314

CVE.ORG link : CVE-2026-26314


JSON object : View

Products Affected

ethereum

  • go_ethereum
CWE
CWE-20

Improper Input Validation