Skip to main content

Vendor archive

ethereum CVEs

Beta · best-effort

39 CVEs tagged to vendor ethereum2 Critical, 21 High, 16 Medium, 0 Low, 0 Unrated.

CVE-2026-26315

Published Feb 19, 2026

go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attack…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-26314

Published Feb 19, 2026

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a speciall…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-26313

Published Feb 19, 2026

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an attacker can cause high memory usage by sending a specially-cra…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22868

Published Jan 13, 2026

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This v…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22862

Published Jan 13, 2026

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This v…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-42319

Published Oct 18, 2023

Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted Graph…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36980

Published Sep 11, 2023

An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casino.balance exceeds the threshold.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40591

Published Sep 6, 2023

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node, can be made to consume unbounded amounts of memory when handling special…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1930

Published Aug 22, 2022

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_stru…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37450

Published Aug 5, 2022

Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve r…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29177

Published May 20, 2022

Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if configured to use high verbosity logging, can be made t…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42219

Published Mar 17, 2022

Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23328

Published Mar 4, 2022

A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23327

Published Mar 4, 2022

A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pendi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43668

Published Nov 18, 2021

Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with "runtime error: invalid memory address or nil…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41173

Published Oct 26, 2021

Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node is susceptible to crash when processing a maliciously crafte…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39137

Published Aug 24, 2021

go-ethereum is the official Go implementation of the Ethereum protocol. In affected versions a consensus-vulnerability in go-ethereum (Geth) could cause a chain split, where vulne…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26800

Published Jan 11, 2021

A stack overflow vulnerability in Aleth Ethereum C++ client version <= 1.8.0 using a specially crafted a config.json file may result in a denial of service.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26265

Published Dec 11, 2020

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26264

Published Dec 11, 2020

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-service vulnerability can make a LES server crash…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14451

Published Dec 2, 2020

An exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds rea…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-26242

Published Nov 25, 2020

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.18, there is a Denial-of-service (crash) during block processing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26241

Published Nov 25, 2020

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. This is a Consensus vulnerability in Geth before version 1.9.17 which can be used to cause…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26240

Published Nov 25, 2020

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to er…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15890

Published Jun 20, 2019

An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs an…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 39 CVEsPage 1 of 2