CVE-2026-26313
MediumAdvisory
Published 18 Feb 2026In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.9
- base score, highest
- EPSS
- 0.006
- 46th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 71
- of 17,781 indexed, latest versions
- Container images
- 67
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Go Ethereum affected by DoS via malicious p2p message
Carried by container images the latest versions of 71 of 17,781 indexed charts deploy, on 67 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.0.0-20220525124254-de23cf910b81, v0.0.0-20220824090902-d901d85377c2, v0.0.0-20240220110850-1ecad30512d7, v0.0.0-20240812063842-d903330c62d7+40 more | 1.17.0 | 67 |
- OSV records
- GHSA-689v-6xwf-5jf3
- Also known as
- GO-2026-4508
Charts affected
71 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| automatap2p-avs | 0.1.0 | 1 of 2See more | 3,621 |
| avap2p-avs | 0.1.0 | 1 of 1See more | 3,298 |
| eigendap2p-avs | 0.1.1 | 2 of 3See more | 2,322 |
| predicatep2p-avs | 0.1.4 | 1 of 1See more | 886 |
| firehose-ethereumpinaxVerified publisher | 0.3.2 | 1 of 2See more | 7,062 |
| chainrss3 | 0.1.28 | 2 of 8See more | 8,528 |
| proxydrss3 | 0.1.0 | 1 of 1See more | 2,110 |
| vsl-chainrss3 | 0.1.0 | 1 of 7See more | 6,044 |
| vsl-rpcrss3 | 0.3.4 | 1 of 4See more | 4,610 |
| vsl-sequencerrss3 | 0.3.4 | 1 of 4See more | 4,610 |
| mev-booststakewise | 1.7.4 | 1 of 1See more | 1,259 |
| ssv-nodestakewise | 2.2.0 | 1 of 2See more | 6,779 |
| agentssynapse | 0.1.30 | 3 of 9See more | 7,244 |
| cctpsynapse | 0.3.0 | 1 of 4See more | 1,815 |
| explorersynapse | 0.2.16 | 2 of 6See more | 8,518 |
| omnirpcsynapse | 0.2.92 | 1 of 2See more | 1,121 |
| promexportersynapse | 0.1.1 | 1 of 1See more | 1,704 |
| screenersynapse | 0.2.5 | 1 of 4See more | 1,091 |
| scribesynapse | 0.2.16 | 2 of 7See more | 2,680 |
| sinnersynapse | 0.1.0 | 1 of 6See more | 1,955 |
| eth-validatorwateim | 1.4.5 | 1 of 3See more | 4,998 |
Container images carrying it
67 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 4e872bc016e8 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 79df4fb20322 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | f5654f745d4c | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 89028adefcff | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 6650119a385f | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | e459ad3ae758 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | b62113fe1b27 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | d7bdfa7b41da | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 8e3cb38953a3 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 81a9ebc899a4 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 2f1408c94168 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 00131e3d1eaf | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 416c1c5aeb86 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | b3de2050460a | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 5e0a3dfa9f96 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 81edba952403 | github.com/ | 1.17.0 | 1 |
| ghcr.io/ | 3e98a98f6074 | github.com/ | 1.17.0 | 1 |