threat
engine
.sh
Back
·
··:··
Home
/
Product
/
ethereum go ethereum
Product
ethereum go ethereum
24 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-26315
< 1.16.9
go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in
7.5
HIGH
CVE-2026-26314
< 1.16.9
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node
7.5
HIGH
CVE-2026-26313
< 1.17.0
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can c
7.5
HIGH
CVE-2026-22868
< 1.16.8
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdow
7.5
HIGH
CVE-2026-22862
< 1.16.8
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdow
7.5
HIGH
CVE-2023-42319
<= 1.13.4
Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory
7.5
HIGH
CVE-2023-40591
>= 1.10.0 and < 1.12.1
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node, can be made to consume
7.5
HIGH
CVE-2022-37450
<= 1.10.21
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a ma
5.9
MEDIUM
CVE-2022-29177
< 1.10.17
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if config
5.9
MEDIUM
CVE-2021-42219
all versions
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an ex
7.5
HIGH
CVE-2022-23328
all versions
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from on
7.5
HIGH
CVE-2022-23327
<= 1.10.12
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas p
7.5
HIGH
CVE-2021-43668
all versions
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash w
5.5
MEDIUM
CVE-2021-41173
< 1.10.9
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node is suscepti
5.7
MEDIUM
CVE-2021-39137
>= 1.10.0 and < 1.10.8
go-ethereum is the official Go implementation of the Ethereum protocol. In affected versions a consensus-vulnerability in go-ether
6.5
MEDIUM
CVE-2020-26265
>= 1.9.4 and < 1.9.20
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before vers
5.3
MEDIUM
CVE-2020-26264
< 1.9.25
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-
6.5
MEDIUM
CVE-2020-26242
< 1.9.18
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, there is a
6.5
MEDIUM
CVE-2020-26241
< 1.9.17
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth
6.5
MEDIUM
CVE-2020-26240
< 1.9.24
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Ge
5.3
MEDIUM
CVE-2018-20421
all versions
Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dyna
7.5
HIGH
CVE-2018-19184
all versions
cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted bytecode.
7.5
HIGH
CVE-2018-16733
< 1.8.14
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start blo
7.5
HIGH
CVE-2018-12018
< 1.8.11
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access vi
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin