{"id":"CVE-2020-26264","aliases":["GHSA-r33q-22hv-j29q","GO-2021-0063"],"url":"https://o3.security/vulnerability/CVE-2020-26264","summary":"Denial of service in github.com/ethereum/go-ethereum","details":"Go Ethereum, or \"Geth\", is the official Golang implementation of the Ethereum protocol. In Geth before version 1.9.25 a denial-of-service vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client. This vulnerability only concerns users explicitly enabling les server; disabling les prevents the exploit. The vulnerability was patched in version 1.9.25.","published":"2020-12-11T17:15:12.793Z","modified":"2026-08-07T15:12:12.626129Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/ethereum/go-ethereum","fixedVersion":"1.9.25"}],"fix":{"url":"https://github.com/ethereum/go-ethereum/commit/bddd103a9f0af27ef533f04e06ea429cf76b6d46","label":"ethereum/go-ethereum@bddd103"},"references":[{"type":"ADVISORY","url":"https://github.com/ethereum/go-ethereum/releases/tag/v1.9.25"},{"type":"ADVISORY","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-r33q-22hv-j29q"},{"type":"FIX","url":"https://github.com/ethereum/go-ethereum/commit/bddd103a9f0af27ef533f04e06ea429cf76b6d46"},{"type":"FIX","url":"https://github.com/ethereum/go-ethereum/pull/21896"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:12:12.626129Z"}}