CVE-2026-26313: Ethereum Go Ethereum

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory usage by sending a specially-crafted p2p message. The issue is resolved in the v1.17.0 release.

Affected products

  • Ethereum Go Ethereum: before 1.17.0 (fixed in 1.17.0)

Published 2026-02-19. Last modified 2026-06-17.