VendorsEthereumgo_ethereumall versions
Vulnerabilities

Ethereum Go Ethereum

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2026-26314
Go Ethereum affected by DoS via malicious p2p message
Published 2026-02-19 · Analyzed
8.7EPSS 0.008
CVE-2018-12018
The GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation because of an integer signedness error for the array index, which allows attackers to launch a Denial of Service attack by sending a packet with a -1 query.Skip value. The vulnerable remote node would be crashed by such an attack immediately, aka the EPoD (Ethereum Packet of Death) issue.
Published 2018-07-05 · Modified
7.5EPSS 0.043
CVE-2020-26240
Erroneous Proof of Work calculation in geth
Published 2020-11-25 · Modified
7.5EPSS 0.019
CVE-2020-26242
Denial of service in geth
Published 2020-11-25 · Modified
7.5EPSS 0.015
CVE-2018-19184
cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted bytecode.
Published 2018-11-12 · Modified
7.5EPSS 0.015
CVE-2018-20421
Go Ethereum (aka geth) 1.8.19 allows attackers to cause a denial of service (memory consumption) by rewriting the length of a dynamic array in memory, and then writing data to a single memory location with a large index number, as demonstrated by use of "assembly { mstore }" followed by a "c[0xC800000] = 0xFF" assignment.
Published 2018-12-24 · Modified
7.5EPSS 0.015
CVE-2022-23328
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's memory pool and then occupy the memory pool to prevent new transactions from entering the pool, resulting in a denial of service (DoS).
Published 2022-03-04 · Modified
7.5EPSS 0.014
CVE-2022-23327
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS).
Published 2022-03-04 · Modified
7.5EPSS 0.014
CVE-2021-39137
Consensus flaw during block processing in go-ethereum
Published 2021-08-24 · Modified
7.5EPSS 0.013
CVE-2018-16733
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start block.
Published 2018-09-08 · Modified
7.5EPSS 0.012
CVE-2021-42219
Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.
Published 2022-03-16 · Modified
7.5EPSS 0.012
CVE-2023-40591
Denial of service via malicious p2p message in go-ethereum
Published 2023-09-06 · Modified
7.5EPSS 0.011
CVE-2023-42319
Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic.
Published 2023-10-18 · Modified
7.5EPSS 0.009
CVE-2026-22862
go-ethereum has a DoS via malicious p2p message
Published 2026-01-13 · Analyzed
7.5EPSS 0.007
CVE-2026-22868
go-ethereum has a DoS via malicious p2p message
Published 2026-01-13 · Analyzed
7.5EPSS 0.006
CVE-2026-26313
Go Ethereum affected by DoS via malicious p2p message
Published 2026-02-19 · Analyzed
7.5EPSS 0.006
CVE-2026-26315
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake
Published 2026-02-19 · Analyzed
7.5EPSS 0.005
CVE-2020-26241
Shallow copy bug in geth
Published 2020-11-25 · Modified
7.1EPSS 0.012
CVE-2020-26264
LES Server DoS via GetProofsV2
Published 2020-12-11 · Modified
6.5EPSS 0.019
CVE-2022-37450
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.
Published 2022-08-05 · Modified
5.9EPSS 0.012
CVE-2022-29177
DoS via malicious p2p message in Go-Ethereum
Published 2022-05-20 · Modified
5.9EPSS 0.011
CVE-2021-41173
DoS via maliciously crafted p2p message
Published 2021-10-26 · Modified
5.7EPSS 0.012
CVE-2021-43668
Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereference" and arise a SEGV signal.
Published 2021-11-18 · Modified
5.5EPSS 0.003
CVE-2020-26265
Consensus flaw during block processing
Published 2020-12-11 · Modified
5.3EPSS 0.009