CVE-2026-26315
Go Ethereum ≤ 1.16.9
Raw vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSummary
CVE-2026-26315 is a medium-severity Observable Discrepancy (CWE-203) vulnerability in Ethereum Go Ethereum. Its CVSS base score is 6.9 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Account Discovery (T1087); ranked at the 37th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-6 (Authentication Feedback) and SI-11 (Error Handling) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2026-26315 is a cryptographic vulnerability in go-ethereum (Geth), a Golang implementation of the Ethereum protocol's execution layer. Prior to version 1.16.9, a flaw in the ECIES cryptography implementation allows an attacker to extract bits of the p2p node key. The issue carries a CVSS score of 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) and maps to CWE-203 (Observable Discrepancy).
Remote attackers with network access to a vulnerable Geth node can exploit this flaw without authentication, privileges, or user interaction. Exploitation enables partial recovery of the p2p node key bits, leading to high confidentiality impact by potentially undermining the security of peer-to-peer communications.
The vulnerability is resolved in Geth releases v1.16.9 and v1.17.0. Geth maintainers recommend rotating the node key after upgrading by removing the file `<datadir>/geth/nodekey` before restarting the software. Additional details are available in the GitHub Security Advisory at https://github.com/ethereum/go-ethereum/security/advisories/GHSA-m6j8-rg6r-7mv8.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-8436
Vulnerability Data
go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attacker may be able to extract bits of the p2p node key. The issue is…
more
resolved in the v1.16.9 and v1.17.0 releases of Geth. Geth maintainers recommend rotating the node key after applying the upgrade, which can be done by removing the file `<datadir>/geth/nodekey` before starting Geth.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 1 hardening rule · 1 OS baseline
—
Mitigating Controls (NIST 800-53 r5) AI
Obscures authentication feedback so that success/failure differences are not observable to attackers.
Requires error messages to avoid revealing exploitable details, directly stopping observable response discrepancies.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent observable response discrepancies via consistent error handling and timing.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Accurate, synchronized timestamps reduce observable timing discrepancies that an attacker could exploit to infer sensitive information or distinguish between success and failure paths.