go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. The problem is resolved in the v1.16.9 and v1.17.0 releases of Geth.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26314.json",
"cwe_ids": [
"CWE-20"
]
}{
"cpe": "cpe:2.3:a:ethereum:go_ethereum:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.16.9"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-21T23:33:38Z"
[
{
"target": {
"function": "secp256k1_ext_scalar_mul",
"file": "crypto/secp256k1/ext.h"
},
"id": "CVE-2026-26314-01f00d10",
"digest": {
"function_hash": "44622898723236999431342883810517715744",
"length": 684.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/ethereum/go-ethereum/commit/895a8597cb16c02203e38707ed2d1da5c500fe60"
},
{
"target": {
"file": "crypto/secp256k1/ext.h"
},
"id": "CVE-2026-26314-06b71dde",
"digest": {
"line_hashes": [
"73264997925125134336452851907900619787",
"188269721243058888770819813480548265224",
"112297746368779224319866079627007684330",
"241840739593558975761918848871078193038",
"23954139147975017107440540459909476981"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/ethereum/go-ethereum/commit/895a8597cb16c02203e38707ed2d1da5c500fe60"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26314.json"