Go Ethereum
24 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Go Ethereum. Use it to gauge the current risk picture and drill into individual advisories.
Go Ethereum CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 2 |
| 2026-02 | 3 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High14
- Medium10
Latest CVEs
The 15 most recently published vulnerabilities affecting Go Ethereum.
- CVE-2026-26315Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake7.5
- CVE-2026-26314Go Ethereum affected by DoS via malicious p2p message7.5
- CVE-2026-26313Go Ethereum affected by DoS via malicious p2p message7.5
- CVE-2026-22868go-ethereum has a DoS via malicious p2p message7.5
- CVE-2026-22862go-ethereum has a DoS via malicious p2p message7.5
- CVE-2023-42319Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: th...7.5
- CVE-2023-40591Denial of service via malicious p2p message in go-ethereum7.5
- CVE-2022-37450Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main...5.9
- CVE-2022-29177DoS via malicious p2p message in Go-Ethereum5.9
- CVE-2021-42219Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing mem...7.5
- CVE-2022-23328A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a...7.5
- CVE-2022-23327A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in...7.5
- CVE-2021-43668Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil pointer dereferen...5.5
- CVE-2021-41173DoS via maliciously crafted p2p message5.7
- CVE-2021-39137Consensus flaw during block processing in go-ethereum6.5
Product grouping is registry-driven, with AI assist and human review. How it works