Cryptographic Flaw in Geth Implementation by Ethereum
CVE-2026-26315
6.9MEDIUM
What is CVE-2026-26315?
A security flaw in the ECIES cryptography implementation of the Geth execution layer may allow attackers to extract bits of the p2p node key. This vulnerability affects versions of Geth prior to 1.16.9. To mitigate this risk, users are urged to upgrade to the latest versions, 1.16.9 or 1.17.0, and to rotate their node keys by deleting the nodekey file located in <datadir>/geth/nodekey before starting Geth.
Affected Version(s)
go-ethereum < 1.16.9
