CVE-2020-26265
In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain.
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-682
- Affected
- ethereum/go ethereum
- Source
- security-advisories@github.com
References
- https://github.com/ethereum/go-ethereum/releases/tag/v1.9.20Third Party Advisory
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-xw37-57qp-9mm4Third Party Advisory
- https://github.com/ethereum/go-ethereum/releases/tag/v1.9.20Third Party Advisory
- https://github.com/ethereum/go-ethereum/security/advisories/GHSA-xw37-57qp-9mm4Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.