Vulnerability Description
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory usage by sending a specially-crafted p2p message. The issue is resolved in the v1.17.0 release.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ethereum | Go Ethereum | < 1.17.0 |
Related Weaknesses (CWE)
References
- https://github.com/ethereum/go-ethereum/releases/tag/v1.17.0Release Notes
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-689v-6xwf-5jf3Vendor Advisory
FAQ
What is CVE-2026-26313?
CVE-2026-26313 is a vulnerability with a CVSS score of 7.5 (HIGH). go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory usage by sending a specially-crafted p2p message. The...
How severe is CVE-2026-26313?
CVE-2026-26313 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-26313?
Check the references section above for vendor advisories and patch information. Affected products include: Ethereum Go Ethereum.