CVE-2020-26265

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-26265
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-26265.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-26265
Aliases
Withdrawn
2024-05-08T06:50:45.416861Z
Published
2020-12-11T17:15:12Z
Modified
2023-11-28T22:16:18.305589Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.

References

Affected packages

Git / github.com/ethereum/go-ethereum

Affected ranges

Type
GIT
Repo
https://github.com/ethereum/go-ethereum
Events

Affected versions

v1.*

v1.9.10
v1.9.11
v1.9.12
v1.9.13
v1.9.14
v1.9.15
v1.9.16
v1.9.17
v1.9.18
v1.9.19
v1.9.4
v1.9.5
v1.9.6
v1.9.7
v1.9.8
v1.9.9