Cryptographic Flaw in Geth Implementation by Ethereum
CVE-2026-26315

6.9MEDIUM

Key Information:

Vendor

Ethereum

Vendor
CVE Published:
19 February 2026

What is CVE-2026-26315?

A security flaw in the ECIES cryptography implementation of the Geth execution layer may allow attackers to extract bits of the p2p node key. This vulnerability affects versions of Geth prior to 1.16.9. To mitigate this risk, users are urged to upgrade to the latest versions, 1.16.9 or 1.17.0, and to rotate their node keys by deleting the nodekey file located in <datadir>/geth/nodekey before starting Geth.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

go-ethereum < 1.16.9

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.