CVE-2026-26313Disclosure(ethereum / go_ethereum)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch ethereum go_ethereum systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory usage by sending a specially-crafted p2p message. The issue is resolved in the v1.17.0 release.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go_ethereum

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
go_ethereum

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-20: 2Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 202-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-26313 go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory usage by sending a … https://www.cve.org/CVERecord?id=CVE-2026-26313

    Post summary

    A CVE‑2026‑26313 vulnerability in go‑ethereum allows memory exhaustion prior to version 1.17.0; no PoC, exploit, patch, or active exploitation is reported.

    00000139
    56.4K followersView on X
  • 알파헌터@AlphaHunterKR
    Disclosure

    🔐 go-ethereum CVE-2026-26313 취약점 공개 — v1.17.0 패치 필수 리소스 제한 없는 할당 버그 → 노드 DoS 공격 가능 야생 익스플로잇 보고는 없으나 취약 버전 노드 긴급 업데이트 권고 Geth 노드 운영자라면 즉시 확인

    Post summary

    A newly disclosed go‑ethereum CVE‑2026‑26313 unbounded allocation bug can cause node DoS, requiring an urgent patch to v1.17.0; no active exploitation has been reported.

    000008
    38 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appethereumgo_ethereum---

Explore more