CVE-2026-22868: go-ethereum has a DoS via malicious p2p message
Impact
An attacker can cause high CPU usage by sending a specially crafted p2p message. More details to be released later.
Credit
This issue was reported to the Ethereum Foundation Bug Bounty Program by @Yenya030
Other sources
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.16.8.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22868?
CVE-2026-22868 is classified as a Denial of Service (DoS) vulnerability that can cause affected systems to crash.
How do I fix CVE-2026-22868?
To mitigate CVE-2026-22868, upgrade your go-ethereum (geth) to version 1.16.8 or later.
Which versions of go-ethereum (geth) are affected by CVE-2026-22868?
CVE-2026-22868 affects all versions of go-ethereum (geth) prior to 1.16.8.
What types of attacks can CVE-2026-22868 lead to?
CVE-2026-22868 can lead to Denial of Service attacks by forcing a vulnerable node to shut down or crash.
How can I determine if my go-ethereum node is vulnerable to CVE-2026-22868?
You can determine if your go-ethereum node is vulnerable to CVE-2026-22868 by checking if its version is earlier than 1.16.8.