CVE-2026-22862: go-ethereum has a DoS via malicious p2p message
Impact
A vulnerable node can be forced to shutdown/crash using a specially crafted message. More details to be released later.
Credit
This issue was reported to the Ethereum Foundation Bug Bounty Program by DELENE TCHIO ROMUALD.
Other sources
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22862?
CVE-2026-22862 is classified as a denial-of-service (DoS) vulnerability.
How do I fix CVE-2026-22862?
To mitigate CVE-2026-22862, upgrade to go-ethereum version 1.16.8 or higher.
What specific attack does CVE-2026-22862 protect against?
CVE-2026-22862 allows a vulnerable go-ethereum node to be shut down or crash via a crafted p2p message.
Which versions of go-ethereum are affected by CVE-2026-22862?
CVE-2026-22862 affects all versions of go-ethereum prior to 1.16.8.
Is CVE-2026-22862 specific to any implementation of Ethereum?
Yes, CVE-2026-22862 specifically affects the go-ethereum (geth) implementation of the Ethereum protocol.