Lighthouse v8.2.3: security release for Ethereum node operators
Lighthouse v8.2.3 (released 2026-10-01) includes security fixes according to its release notes. Ethereum node operators running Lighthouse should review and upgrade.
Vuln-watch · relayed from an upstream security release; see Source & attribution below
Summary
Lighthouse v8.2.3 (released 2026-10-01) includes security fixes according to its release notes. Ethereum node operators running Lighthouse should review and upgrade.
Affected
- Lighthouse (sigp/lighthouse) versions before v8.2.3
From the release notes
## Summary This medium-priority release contains fixes for security vulnerabilities and is recommended for all mainnet users. If you are running a node on Sepolia you'll need v8.3.0-rc.0 instead: https://github.com/sigp/lighthouse/releases/tag/v8.3.0-rc.0 ## Update Priority This table provides priorities for which classes of users should update particular components. User Class Beacon Node Validator Client Staking Users Medium Low Non-Staking Users Medium --- See Update Priorities for more information about this table. ## Security Content This section will be updated with security advisories as they are made public. We are not disclosing the security content of this release in order to give users time to upgrade. ## Known Issues Data column backfill can OOM, particularly on Gnosis chain. This is fixed in v8.3.0-rc.0 and will be included in v8.3.0 shortly. We do not recommend
Recommended actions
- Upgrade Lighthouse to v8.2.3 or later
- Check the release notes for any coordinated upgrade deadline or required configuration change
Source & attribution
This 0xCERT advisory relays the Lighthouse v8.2.3 release notes: https://github.com/sigp/lighthouse/releases/tag/v8.2.3. Refer to the upstream project for the authoritative record and any follow-up security advisories.
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-10-01 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0184/signed.txt | gpg --verify