-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0216 ============================================================ Advisory-ID: 0xCERT-2026-0216 Severity: High Published: 2026-01-13T21:55:29.000Z Updated: 2026-10-08T22:48:25.539Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0216 Title: go-ethereum is vulnerable to high CPU usage leading to DoS via malicious p2p message Summary - ------- go-ethereum is vulnerable to high CPU usage leading to DoS via malicious p2p message. Impact An attacker can cause high CPU usage by sending a specially crafted p2p message. More details to be released later. Details - ------- Summary Impact An attacker can cause high CPU usage by sending a specially crafted p2p message. More details to be released later. Affected - - github.com/ethereum/go-ethereum (go) <= 1.16.7 — fixed in 1.16.8 Severity High (CVSS 7.1), as rated by the upstream advisory. Recommended actions - - Upgrade github.com/ethereum/go-ethereum to 1.16.8 or later Source & attribution This 0xCERT advisory summarises GHSA-mq3p-rrmp-79jg / CVE-2026-22868 from the GitHub Advisory Database, credited upstream to Yenya030: https://github.com/advisories/GHSA-mq3p-rrmp-79jg. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/advisories/GHSA-mq3p-rrmp-79jg - - CVE-2026-22868 - - https://github.com/ethereum/go-ethereum/security/advisories/GHSA-mq3p-rrmp-79jg - - https://nvd.nist.gov/vuln/detail/CVE-2026-22868 - - https://github.com/ethereum/go-ethereum/commit/abeb78c647e354ed922726a1d719ac7bc64a07e2 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrI9WUJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmcl3tBJkMo96AN7XNXrs9+57+qkElCOWoVjURuG MkIJ/RYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAABd0QEAvpogCJxByhn19k/g Oc62D1CyjlgZcc2QlxTb+/dWNykBAMmLKVPqznK4hrb5sI2S5snbTsXUujj9 zMZnJAygbDQM =LgW+ -----END PGP SIGNATURE-----