-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0219 ============================================================ Advisory-ID: 0xCERT-2026-0219 Severity: Medium Published: 2026-02-18T22:34:49.000Z Updated: 2026-10-08T22:48:26.400Z Chains: Ethereum URL: https://www.0xcert.com/advisory/0xCERT-2026-0219 Title: Go Ethereum affected by DoS via malicious p2p message Summary - ------- Go Ethereum affected by DoS via malicious p2p message. An attacker can cause high memory usage by sending a specially-crafted p2p message. More details to be released later. The issue is resolved in the v1.17.0 release. Details - ------- Summary An attacker can cause high memory usage by sending a specially-crafted p2p message. More details to be released later. The issue is resolved in the v1.17.0 release. Affected - - github.com/ethereum/go-ethereum (go) < 1.17.0 — fixed in 1.17.0 Severity Medium (CVSS 6.9), as rated by the upstream advisory. Recommended actions - - Upgrade github.com/ethereum/go-ethereum to 1.17.0 or later Source & attribution This 0xCERT advisory summarises GHSA-689v-6xwf-5jf3 / CVE-2026-26313 from the GitHub Advisory Database, credited upstream to revofusion: https://github.com/advisories/GHSA-689v-6xwf-5jf3. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/advisories/GHSA-689v-6xwf-5jf3 - - CVE-2026-26313 - - https://github.com/ethereum/go-ethereum/security/advisories/GHSA-689v-6xwf-5jf3 - - https://github.com/ethereum/go-ethereum/releases/tag/v1.17.0 - - https://nvd.nist.gov/vuln/detail/CVE-2026-26313 - - https://pkg.go.dev/vuln/GO-2026-4508 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrI9V0JEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmcq8jCRnPhYPygHeDXq7OG0mT6LffSOIGQFhZ9M xRm/ohYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAAA/3QEAn5bkORNcWIMXRvIR ZnokAUnLmCcQ5z/PFnh/DaXYWr4A/iqHq23JP+X1rSASlcudXutLDBznZwM4 k47OrOIbYsoO =QX14 -----END PGP SIGNATURE-----