Vulnerability Report: GO-2026-4511
- CVE-2026-26315, GHSA-m6j8-rg6r-7mv8
- Affects: github.com/ethereum/go-ethereum
- Published: Feb 24, 2026
Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake in github.com/ethereum/go-ethereum
For detailed information about this vulnerability, visit https://github.com/ethereum/go-ethereum/security/advisories/GHSA-m6j8-rg6r-7mv8.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.16.9
Aliases
References
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-m6j8-rg6r-7mv8
- https://github.com/ethereum/go-ethereum/commit/46bee92f9e64c0a06a12586a5d21cffc49d1ba8e
- https://github.com/ethereum/go-ethereum/pull/33669
- https://github.com/ethereum/go-ethereum/releases/tag/v1.16.9
- https://vuln.go.dev/ID/GO-2026-4511.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.