CVE-2026-26314Patch(ethereum / go_ethereum)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ethereum go_ethereum systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. The problem is resolved in the v1.16.9 and v1.17.0 releases of Geth.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go_ethereum

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 8d ago at 1 mentions (2026-02-17); latest day: 1
  • 9 total mentions across 9 days

Affected systems

Vendors
Products
go_ethereum

Deep dive

Activity timeline9 mentions / 9d
00111Mentions · 2026-02-17: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-03-06: 1Mentions · 2026-03-18: 1Mentions · 2026-04-16: 1Mentions · 2026-06-01: 1Mentions · 2026-06-26: 1Mentions · 2026-07-24: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-06: 1Technical Details · 2026-04-16: 1Technical Details · 2026-07-24: 102-1702-1902-2003-0603-1804-1606-0106-2607-24
Signal classification4 categories
Patch
444.4%
Disclosure
222.2%
General
222.2%
PoC
111.1%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-171
Patch1
2026-02-191
Patch1
2026-02-201
Patch1
2026-03-061
Disclosure1
2026-03-181
Patch1
2026-04-161
Disclosure1
2026-06-011
General1
2026-06-261
General1
2026-07-241
PoC1
Full discourse9 posts
  • VulSight@VulsightSec
    General

    A lot of security firms will tell you what they're capable of. The ones worth hiring let the work tell you. Ours says: → Top 10 on the @immunefi 2026 Whitehat Leaderboard 🛡️ → 100+ audits across EVM, Move & Rust → $845K+ in bug bounties → A CVE (CVE-2026-26314) in Ethereum's Geth client → Ranked #16 all-time on @cantinaxyz Global Leaderboard → Peaked at Top 3 on Immunefi earlier this year The codebase doesn't lie. Neither does the leaderboard.

    Post summary

    The post notes the discovery of CVE-2026-26314 in Ethereum's Geth client but offers no additional technical, exploit, or mitigation information.

    53197174.3K
    1.3K followersView on X
  • Story Engineers@StoryEngs
    Patch

    Yasunari (Story-Geth v1.2.1) ⚠️ This release merges upstream security patches addressing CVE-2026-26314 and CVE-2026-26315, and added DNS resolution support for bootnodes. If you're running a node, upgrading is required. Read More ↴

    Post summary

    The Yasunari release includes patches for CVE‑2026‑26314 and CVE‑2026‑26315; users should upgrade to mitigate the vulnerabilities.

    5312601.2K
    51.8K followersView on X
  • Samy | Elios@stableoperator
    PoC

    @VulsightSec And those eyes have receipts, all public: - Top 16 all-time on Cantina by public earnings\ - 1st place in the USDaf competition ($67.5k payout) - A High-severity vuln in Geth, responsibly disclosed (CVE-2026-26314) Proof is in the pudding.

    Post summary

    The tweet announces a high‑severity vulnerability in Geth (CVE-2026‑26314), claiming proof exists but providing no PoC code, exploit details, active exploitation evidence, or patch information.

    13060130
    1.7K followersView on X
  • Grok@grok
    Patch

    The Geth v1.16.9 security release fixes two issues: - CVE-2026-26314 (High): DoS vulnerability via malicious p2p messages that could crash or shut down nodes. - CVE-2026-26315 (Moderate): Flaw in ECIES public key validation during RLPx handshake, allowing potential extraction of p2p node key bits. Code diffs include stricter curve point checks in crypto/ecies and secp256k1, plus new tests. Upgrade and rotate your node key by deleting DATADIR/geth/nodekey. For v1.17.0, it adds eth_getProof support but no security fixes.

    Post summary

    The announcement highlights a Geth security release patching two CVEs, provides upgrade guidance, and explains the technical nature of the vulnerabilities.

    100621.2K
    8.0M followersView on X
  • VulSight@VulsightSec
    Disclosure

    Vulsight team is at @ParisBlockWeek 2026! 🇫🇷 100+ audits completed. $845K+ in bug bounties. $2B+ secured in TVL. Top 15 All time on Cantina leaderboard. A published CVE (CVE-2026-26314) DoS on Ethereum's Geth codebase. Securing protocols across EVM, Move and Rust. With thousands of finance leaders, policymakers, and builders in one place, we're excited to talk about what matters most: making Web3 safer for everyone. Let's connect — DMs are open.

    Post summary

    The post announces that Vulsight published CVE‑2026‑26314, a DoS vulnerability in Ethereum’s Geth codebase, while highlighting the team's audit achievements.

    00050473
    1.3K followersView on X
  • VulSight@VulsightSec
    Disclosure

    Client and node vulnerabilities can halt entire networks. We know because we found one a high-severity consensus bug in Ethereum's Geth client (CVE-2026-26314) No smart contract audit in the world would have caught that.

    Post summary

    The text reports the discovery of a high‑severity consensus bug in Ethereum’s Geth client (CVE‑2026‑26314) but does not provide evidence of exploitation, a PoC, or a patch.

    10010162
    1.2K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-26314: Malicious P2P message can crash go-ethereum (Geth) nodes remotely, no login needed. Upgrade to 1.16.9+ or 1.17.0 and regenerate your node key to stay online. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-26314 #Ethereum #infosec #blockchain

    Post summary

    CVE-2026-26314 causes a remote crash in go-ethereum via malicious P2P messages, mitigated by upgrading to 1.16.9+ or 1.17.0 and regenerating the node key.

    0002055
    50 followersView on X
  • ShadowWalker@ItsShad0wWalker
    General

    @GuiBibeau This fits our stack at @VulsightSec . Smart contract side: Top 16 all-time on Cantina, Top 10 on Immunefi 2026, recently disclosed CVE-2026-26314 in Ethereum's Geth client. DM open, happy to help.

    Post summary

    The tweet announces that CVE‑2026‑26314 was recently disclosed for Ethereum’s Geth client, noting the organization’s interest without providing additional technical details or evidence of exploitation.

    00010206
    235 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-26314 go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash usi… https://www.cve.org/CVERecord?id=CVE-2026-26314

    Post summary

    CVE‑2026‑26314 causes node crashes in go‑ethereum before v1.16.9, but the issue is fixed in that release.

    00000320
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appethereumgo_ethereum---

Explore more