Ethereum's vulnerability profile centers on a narrow but prominent set of blockchain client implementations, including Go Ethereum and C++ Ethereum variants, that serve as critical infrastructure for consensus participation and network synchronization. Vulnerabilities affecting these clients span weakness classes rooted in authorization logic, input validation at the protocol and transaction-processing boundary, arithmetic correctness in state calculations, and resource-consumption controls—exposures inherent to decentralized consensus systems where malformed or malicious inputs must be validated without trust. The moderate tendency of these disclosures toward serious outcomes reflects the high-value and availability-critical role these clients play in the blockchain ecosystem; defenders operating validators or full nodes should treat client advisories as urgent and prioritize rapid patching to maintain consensus integrity and prevent state divergence. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ethereum over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14451CRITICAL An exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read | Dec 2, 2020 | 10.0 | 33 | NO | NO |
CVE-2018-15890CRITICAL An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and | Jun 20, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-18920HIGH Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with '"stack": [100, 100, 0]' where b'\x' was expected, resulting | Nov 12, 2018 | 8.8 | 28 | NO | NO |
CVE-2026-26314HIGH go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially | Feb 19, 2026 | 7.5 | 27 | NO | NO |
CVE-2022-23328HIGH A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of | Mar 4, 2022 | 7.5 | 27 | NO | NO |
CVE-2022-23327HIGH A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pendin | Mar 4, 2022 | 7.5 | 27 | NO | NO |
CVE-2026-22862HIGH go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vu | Jan 13, 2026 | 7.5 | 26 | NO | NO |
CVE-2017-14457HIGH An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart | Jan 19, 2018 | 8.2 | 26 | NO | NO |
CVE-2017-12118HIGH An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). An attacker can send JSON | Jan 19, 2018 | 8.1 | 26 | NO | NO |
CVE-2017-12113HIGH An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e1015743b95821849d001618a7ce82c7c073768). A JSON request can ca | Jan 19, 2018 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ethereum.
Media articles that mention a CVE ID that affects a product developed by Ethereum — matched by CVE ID, not by vendor name.