CVE-2026-22866 describes a signature forgery vulnerability in the Ethereum Name Service (ENS) versions 1.6.2 and prior, specifically within the RSASHA256Algorithm and RSASHA1Algorithm contracts. These contracts inadequately validate PKCS#1 v1.5 padding, making them susceptible to Bleichenbacher's 2006 attack. This flaw allows attackers to fraudulently claim domains under ENS-supported TLDs like .cc and .name if those TLDs use RSA keys with low public exponents (e=3). The vulnerability has a CVSSv4 score of 2.7 (LOW), indicating a network-based attack with low complexity and no required privileges or user interaction. While the direct impact on confidentiality, integrity, and availability is rated as none or low, the ability to fraudulently claim domains represents a significant integrity risk for affected ENS users. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.2CPE matchmatch criteria | cpe:2.3:a:ens.domains:ethereum_name_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.