GHSA-pvx3-gm3c-gmprHighCVSS 7.5

Denial of Service in Go-Ethereum

Published
March 5, 2022
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS).

🎯 Affected products1

  • go/github.com/ethereum/go-ethereum:<= 1.10.12

🔗 References (5)