High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum
02 / AFFECTED SOFTWARE
Affected packages
176 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.
High CPU usage leading to DoS via malicious p2p message in github.com/ethereum/go-ethereum
**Impact** An attacker can cause high CPU usage by sending a specially crafted p2p message. More details to be released later. **Credit** This issue was reported to the Ethereum Foundation Bug Bounty Program by @Yenya030
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22868.json
- https://github.com/ethereum/go-ethereum/commit/abeb78c647e354ed922726a1d719ac7bc64a07e2
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-mq3p-rrmp-79jg
- https://nvd.nist.gov/vuln/detail/CVE-2026-22868
- https://github.com/ethereum/go-ethereum