Home/Product/ethereum go ethereum
Product

ethereum go ethereum

24 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-26315
< 1.16.9
go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in
7.5HIGH
CVE-2026-26314
< 1.16.9
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node
7.5HIGH
CVE-2026-26313
< 1.17.0
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can c
7.5HIGH
CVE-2026-22868
< 1.16.8
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdow
7.5HIGH
CVE-2026-22862
< 1.16.8
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdow
7.5HIGH
CVE-2023-42319
<= 1.13.4
Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory
7.5HIGH
CVE-2023-40591
>= 1.10.0 and < 1.12.1
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node, can be made to consume
7.5HIGH
CVE-2022-37450
<= 1.10.21
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a ma
5.9MEDIUM
CVE-2022-29177
< 1.10.17
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if config
5.9MEDIUM
CVE-2021-42219
all versions
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an ex
7.5HIGH
CVE-2022-23328
all versions
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from on
7.5HIGH
CVE-2022-23327
<= 1.10.12
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas p
7.5HIGH
CVE-2021-43668
all versions
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash w
5.5MEDIUM
CVE-2021-41173
< 1.10.9
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node is suscepti
5.7MEDIUM
CVE-2021-39137
>= 1.10.0 and < 1.10.8
go-ethereum is the official Go implementation of the Ethereum protocol. In affected versions a consensus-vulnerability in go-ether
6.5MEDIUM
CVE-2020-26265
>= 1.9.4 and < 1.9.20
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before vers
5.3MEDIUM
CVE-2020-26264
< 1.9.25
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-
6.5MEDIUM
CVE-2020-26242
< 1.9.18
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, there is a
6.5MEDIUM
CVE-2020-26241
< 1.9.17
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth
6.5MEDIUM
CVE-2020-26240
< 1.9.24
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Ge
5.3MEDIUM
CVE-2018-20421
all versions
Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dyna
7.5HIGH
CVE-2018-19184
all versions
cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted bytecode.
7.5HIGH
CVE-2018-16733
< 1.8.14
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start blo
7.5HIGH
CVE-2018-12018
< 1.8.11
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access vi
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin