ethereum has 6 CVEs on record between 2021 and 2022. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. Most affected products: github.com/ethereum/go-ethereum (4), go_ethereum (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- github.com/ethereum/go-ethereum 4
- go_ethereum 2
Worst active — by depth score
CVE-2022-23328High· 7.5A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all o…42CVE-2022-23327High· 7.5A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a …42CVE-2021-39137Medium· 6.5Ethereum Contains Consensus Flaw During Block Processing36CVE-2020-26242Medium· 6.5Denial of service in geth36CVE-2020-26241Medium· 6.5Shallow copy bug in geth36
ethereum vulnerabilities
CVEs affecting ethereum, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2022-23328High· 7.5A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all o…
A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all o…
CVE-2022-23327High· 7.5A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a …
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a …
CVE-2021-41173Medium· 5.7Geth Node Vulnerable to DoS via maliciously crafted p2p message
Geth Node Vulnerable to DoS via maliciously crafted p2p message
CVE-2021-39137Medium· 6.5Ethereum Contains Consensus Flaw During Block Processing
Ethereum Contains Consensus Flaw During Block Processing
CVE-2020-26242Medium· 6.5Denial of service in geth
Denial of service in geth
CVE-2020-26241Medium· 6.5Shallow copy bug in geth
Shallow copy bug in geth