CVE-2020-26265: Consensus flaw during block processing
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-26265?
CVE-2020-26265 is a consensus-vulnerability in the Go Ethereum (Geth) implementation of the Ethereum protocol.
What is the severity of CVE-2020-26265?
CVE-2020-26265 has a severity value of 5.3, which is considered medium.
What software is affected by CVE-2020-26265?
The affected software is Go Ethereum (Geth) with versions between 1.9.4 and 1.9.20.
What is the fix for CVE-2020-26265?
The fix for CVE-2020-26265 is included in the Paragade release of Go Ethereum (Geth) version 1.9.20.
Where can I find more information about CVE-2020-26265?
You can find more information about CVE-2020-26265 on the GitHub security advisories page: [GitHub Security Advisories](https://github.com/ethereum/go-ethereum/security/advisories/GHSA-xw37-57qp-9mm4)