CVE-2024-32972: Ethereum Go-Ethereum
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. The fix has been included in geth version `1.13.15` and onwards.
Affected products
- Ethereum Go-Ethereum: before 1.13.15 (fixed in 1.13.15)
- Ethereum Go Ethereum: before 1.13.15 (fixed in 1.13.15)
Published 2024-05-06. Last modified 2026-06-17.