CVE-2020-26265: Ethereum Go Ethereum
Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.
Affected products
- Ethereum Go Ethereum: from 1.9.4, before 1.9.20 (fixed in 1.9.20)
Published 2020-12-11. Last modified 2026-06-17.