Skip to content

Improper ECIES Public Key Validation in RLPx Handshake

Moderate
fjl published GHSA-m6j8-rg6r-7mv8 Feb 17, 2026

Package

No package listed

Affected versions

<= 1.16.8

Patched versions

>= 1.16.9

Description

Impact

Through a flaw in the ECIES cryptography implementation, an attacker may be able to extract bits of the p2p node key.

Patches

The issue is resolved in the v1.16.9 and v1.17.0 releases of Geth. We recommend rotating the node key after applying the upgrade, which can be done by removing the file <datadir>/geth/nodekey before starting Geth.

Credit

The issue was reported as a public pull request to go-ethereum by @fengjian.

Severity

Moderate

CVE ID

CVE-2026-26315

Weaknesses

No CWEs

Credits