CVE-2026-26315
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Description
go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attacker may be able to extract bits of the p2p node key. The issue is resolved in the v1.16.9 and v1.17.0 releases of Geth. Geth maintainers recommend rotating the node key after applying the upgrade, which can be done by removing the file `<datadir>/geth/nodekey` before starting Geth.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-203
Source
GitHub
Vendor
go
Product
github.com/ethereum/go-ethereum
External References
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-m6j8-rg6r-7mv8
- https://github.com/ethereum/go-ethereum/pull/33669
- https://github.com/ethereum/go-ethereum/commit/46bee92f9e64c0a06a12586a5d21cffc49d1ba8e
- https://github.com/ethereum/go-ethereum/releases/tag/v1.16.9
- https://github.com/advisories/GHSA-m6j8-rg6r-7mv8
Discussion (0)
Add Comment
No comments yet. Be the first!