Erigon v3.6.1: security release for Ethereum node operators
Erigon v3.6.1 (released 2026-09-09) includes security fixes according to its release notes. Ethereum node operators running Erigon should review and upgrade.
Vuln-watch · relayed from an upstream security release; see Source & attribution below
Summary
Erigon v3.6.1 (released 2026-09-09) includes security fixes according to its release notes. Ethereum node operators running Erigon should review and upgrade.
Affected
- Erigon (erigontech/erigon) versions before v3.6.1
From the release notes
## Erigon v3.6.1 — Upstream Underbelly v3.6.1 is a bugfix and security release recommended for all users. It fixes a downloader regression that could silently replace a valid local snapshot (#23859), a peer-ban bypass that let a banned Caplin peer reconnect immediately (#23866), an index-build defect that could leave stale bits in a recsplit index after a salt-collision retry (#23858), and bumps google.golang.org/grpc for two HIGH-severity CVEs (#23888). It is a drop-in upgrade from 3.6.0 — no re-sync required. ## Highlights - db/downloader: keep local snapshot data once the initial download is complete (#23859) by @AskAlexSharov — a locally-differing .seg that no longer matched its .torrent was silently replaced even after preverified.toml existed; it is now kept and registered for seeding, with a warn-level log when a mismatched file is still replaced. Fixes #21522. - cl/sentinel:
Recommended actions
- Upgrade Erigon to v3.6.1 or later
- Check the release notes for any coordinated upgrade deadline or required configuration change
Source & attribution
This 0xCERT advisory relays the Erigon v3.6.1 release notes: https://github.com/erigontech/erigon/releases/tag/v3.6.1. Refer to the upstream project for the authoritative record and any follow-up security advisories.
References
- https://github.com/erigontech/erigon/releases/tag/v3.6.1
- CVE-2026-84304
- CVE-2026-84445
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-09 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0165/signed.txt | gpg --verify