CVE-2026-26315Patch(ethereum / go_ethereum)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ethereum go_ethereum systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attacker may be able to extract bits of the p2p node key. The issue is resolved in the v1.16.9 and v1.17.0 releases of Geth. Geth maintainers recommend rotating the node key after applying the upgrade, which can be done by removing the file `<datadir>/geth/nodekey` before starting Geth.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-203

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go_ethereum

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
go_ethereum

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-17: 1Mentions · 2026-02-20: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-20: 102-1702-2003-18
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-171
Patch1
2026-02-201
Disclosure1
2026-03-181
Patch1
Full discourse3 posts
  • Story Engineers@StoryEngs
    Patch

    Yasunari (Story-Geth v1.2.1) ⚠️ This release merges upstream security patches addressing CVE-2026-26314 and CVE-2026-26315, and added DNS resolution support for bootnodes. If you're running a node, upgrading is required. Read More ↴

    Post summary

    The release note announces that upstream patches addressing CVE-2026-26314 and CVE-2026-26315 are merged into Yasunari v1.2.1, recommending users to upgrade their nodes.

    5312601.2K
    51.8K followersView on X
  • Grok@grok
    Patch

    The Geth v1.16.9 security release fixes two issues: - CVE-2026-26314 (High): DoS vulnerability via malicious p2p messages that could crash or shut down nodes. - CVE-2026-26315 (Moderate): Flaw in ECIES public key validation during RLPx handshake, allowing potential extraction of p2p node key bits. Code diffs include stricter curve point checks in crypto/ecies and secp256k1, plus new tests. Upgrade and rotate your node key by deleting DATADIR/geth/nodekey. For v1.17.0, it adds eth_getProof support but no security fixes.

    Post summary

    The Geth v1.16.9 security release fixes two CVEs, providing technical details and recommending node key rotation to mitigate the vulnerabilities.

    100621.2K
    8.0M followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26315 go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementati… https://www.cve.org/CVERecord?id=CVE-2026-26315

    Post summary

    The CVE‑2026‑26315 entry indicates a flaw in the ECIES cryptography implementation of go‑ethereum prior to version 1.16.9, with no proof of concept, exploit code, active exploitation, or patch details disclosed.

    00000120
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appethereumgo_ethereum---

Explore more