{"id":"CVE-2021-43668","aliases":["GHSA-5m8f-chrv-7rw5"],"url":"https://o3.security/vulnerability/CVE-2021-43668","summary":"Denial of Service in Go-Ethereum","details":"Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They will crash with \"runtime error: invalid memory address or nil pointer dereference\" and arise a SEGV signal.","published":"2021-11-18T16:15:09.230Z","modified":"2026-08-07T19:47:03.484366Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00251,"percentile":0.16827,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/ethereum/go-ethereum","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/ethereum/go-ethereum/issues/23866"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T19:47:03.484366Z"}}