Insufficient verification of data authenticity in go-ethereum - CVE-2026-26315
Published: April 27, 2026
go-ethereum
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper public key validation in the ECIES cryptography implementation in the RLPx handshake when processing handshake data. A remote attacker can send a specially crafted handshake to disclose sensitive information.
The issue may allow extraction of bits of the p2p node key.