CVE-2026-26313
Impact
An attacker can cause high memory usage by sending a specially-crafted p2p message.
More details to be released later.
Patches
The issue is resolved in the v1.17.0 release.
Credit
This issue was reported to the Ethereum Foundation Bug Bounty Program by @revofusion
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-689v-6xwf-5jf3, https://nvd.nist.gov/vuln/detail/CVE-2026-26313, https://github.com/ethereum/go-ethereum, https://github.com/ethereum/go-ethereum/releases/tag/v1.17.0, https://pkg.go.dev/vuln/GO-2026-4508
