Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
Medium0xCERT-2026-0165·

Erigon v3.6.1: security release for Ethereum node operators

Erigon v3.6.1 (released 2026-09-09) includes security fixes according to its release notes. Ethereum node operators running Erigon should review and upgrade.

Vuln-watch · relayed from an upstream security release; see Source & attribution below

Affected chainsEthereum

Summary

Erigon v3.6.1 (released 2026-09-09) includes security fixes according to its release notes. Ethereum node operators running Erigon should review and upgrade.

Affected

  • Erigon (erigontech/erigon) versions before v3.6.1

From the release notes

## Erigon v3.6.1 — Upstream Underbelly v3.6.1 is a bugfix and security release recommended for all users. It fixes a downloader regression that could silently replace a valid local snapshot (#23859), a peer-ban bypass that let a banned Caplin peer reconnect immediately (#23866), an index-build defect that could leave stale bits in a recsplit index after a salt-collision retry (#23858), and bumps google.golang.org/grpc for two HIGH-severity CVEs (#23888). It is a drop-in upgrade from 3.6.0 — no re-sync required. ## Highlights - db/downloader: keep local snapshot data once the initial download is complete (#23859) by @AskAlexSharov — a locally-differing .seg that no longer matched its .torrent was silently replaced even after preverified.toml existed; it is now kept and registered for seeding, with a warn-level log when a mismatched file is still replaced. Fixes #21522. - cl/sentinel:

Recommended actions

  • Upgrade Erigon to v3.6.1 or later
  • Check the release notes for any coordinated upgrade deadline or required configuration change

Source & attribution

This 0xCERT advisory relays the Erigon v3.6.1 release notes: https://github.com/erigontech/erigon/releases/tag/v3.6.1. Refer to the upstream project for the authoritative record and any follow-up security advisories.

References

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-09-09 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0165/signed.txt | gpg --verify