CVE-2026-26314: Ethereum Go Ethereum

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. The problem is resolved in the v1.16.9 and v1.17.0 releases of Geth.

Affected products

  • Ethereum Go Ethereum: before 1.16.9 (fixed in 1.16.9)

Published 2026-02-19. Last modified 2026-06-17.