logo

Database

Asymmetric denial of service - ReDoS In github.com/ethereum/go-ethereum

Description

go-ethereum is vulnerable to high CPU usage leading to DoS via malicious p2p message Impact

An attacker can cause high CPU usage by sending a specially crafted p2p message. More details to be released later.

Credit

This issue was reported to the Ethereum Foundation Bug Bounty Program by @Yenya030

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions