StackRadar

CVE-2026-26315

Medium

Advisory

Published 18 Feb 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
71
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake

Carried by container images the latest versions of 71 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
github.com/ethereum/go-ethereumgolangv0.0.0-20220525124254-de23cf910b81, v0.0.0-20220824090902-d901d85377c2, v0.0.0-20240220110850-1ecad30512d7, v0.0.0-20240812063842-d903330c62d7+40 more1.16.967
OSV records
GHSA-m6j8-rg6r-7mv8
Also known as
GO-2026-4511

Charts affected

71 by stars
ChartLatestAffected imagesRadar Score
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
github.com/ethereum/go-ethereum@v1.14.3
1.16.9

Open the chart page →

3,621
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
github.com/ethereum/go-ethereum@v1.13.14
1.16.9

Open the chart page →

3,298
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
github.com/ethereum/go-ethereum@v1.14.0
1.16.9
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
github.com/ethereum/go-ethereum@v1.14.0
1.16.9

Open the chart page →

2,322
predicatep2p-avs0.1.41 of 1See more

predicate p2p-avs 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
github.com/ethereum/go-ethereum@v1.13.14
1.16.9

Open the chart page →

886
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
github.com/ethereum/go-ethereum@v0.0.0-20250725230142-195b2bec9190+dirty
1.16.9

Open the chart page →

7,062
chainrss30.1.282 of 8See more

chain rss3 0.1.28

2 of the 8 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/ethereum/go-ethereum@v0.0.0-20240220110850-1ecad30512d7
1.16.9
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
github.com/ethereum/go-ethereum@v1.13.4
1.16.9

Open the chart page →

8,528
proxydrss30.1.01 of 1See more

proxyd rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
github.com/ethereum/go-ethereum@v1.13.11
1.16.9

Open the chart page →

2,110
vsl-chainrss30.1.01 of 7See more

vsl-chain rss3 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/ethereum/go-ethereum@v0.0.0-20240220110850-1ecad30512d7
1.16.9

Open the chart page →

6,044
vsl-rpcrss30.3.41 of 4See more

vsl-rpc rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/ethereum/go-ethereum@v0.0.0-20240220110850-1ecad30512d7
1.16.9

Open the chart page →

4,610
vsl-sequencerrss30.3.41 of 4See more

vsl-sequencer rss3 0.3.4

1 of the 4 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/ethereum/go-ethereum@v0.0.0-20240220110850-1ecad30512d7
1.16.9

Open the chart page →

4,610
mev-booststakewise1.7.41 of 1See more

mev-boost stakewise 1.7.4

1 of the 1 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
flashbots/mev-boost:1.8.07c486b5789da
github.com/ethereum/go-ethereum@v1.14.7
1.16.9

Open the chart page →

1,259
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/ethereum/go-ethereum@v1.14.8
1.16.9

Open the chart page →

6,779
agentssynapse0.1.303 of 9See more

agents synapse 0.1.30

3 of the 9 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/ethereum/go-ethereum@v1.10.26
1.16.9
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/ethereum/go-ethereum@v1.13.8
1.16.9
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/ethereum/go-ethereum@v1.10.26
1.16.9

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/ethereum/go-ethereum@v1.10.26
1.16.9

Open the chart page →

1,815
explorersynapse0.2.162 of 6See more

explorer synapse 0.2.16

2 of the 6 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/ethereum/go-ethereum@v1.13.8
1.16.9
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/ethereum/go-ethereum@v1.13.8
1.16.9

Open the chart page →

8,518
omnirpcsynapse0.2.921 of 2See more

omnirpc synapse 0.2.92

1 of the 2 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/ethereum/go-ethereum@v1.13.8
1.16.9

Open the chart page →

1,121
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/ethereum/go-ethereum@v1.10.26
1.16.9

Open the chart page →

1,704
screenersynapse0.2.51 of 4See more

screener synapse 0.2.5

1 of the 4 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/ethereum/go-ethereum@v1.13.8
1.16.9

Open the chart page →

1,091
scribesynapse0.2.162 of 7See more

scribe synapse 0.2.16

2 of the 7 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/omnirpc:latest5217e3d1fc70
github.com/ethereum/go-ethereum@v1.13.8
1.16.9
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/ethereum/go-ethereum@v1.13.8
1.16.9

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/ethereum/go-ethereum@v1.11.6
1.16.9

Open the chart page →

1,955
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2026-26315.

Container imageDigestPackageFixed in
ethereum/client-go:latest37575ec10fbc
github.com/ethereum/go-ethereum@v0.0.0-20260904203113-d799b1a3f20f+dirty
1.16.9

Open the chart page →

4,998

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
github.com/ethereum/go-ethereum@v1.16.7
1.16.9
1
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
github.com/ethereum/go-ethereum@v1.16.7
1.16.9
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
github.com/ethereum/go-ethereum@v1.14.13
1.16.9
1
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
github.com/ethereum/go-ethereum@v1.10.18
1.16.9
1
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
github.com/ethereum/go-ethereum@v1.14.0
1.16.9
1
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
github.com/ethereum/go-ethereum@v1.14.0
1.16.9
1
ghcr.io/predicatelabs/operator:v1.0.5b62113fe1b27
github.com/ethereum/go-ethereum@v1.13.14
1.16.9
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
github.com/ethereum/go-ethereum@v0.0.0-20250725230142-195b2bec9190+dirty
1.16.9
1
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
github.com/ethereum/go-ethereum@v0.0.0-20260217182555-6cf2f05a5b11+dirty
1.16.9
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/ethereum/go-ethereum@v1.10.26
1.16.9
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/ethereum/go-ethereum@v1.10.26
1.16.9
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/ethereum/go-ethereum@v1.13.8
1.16.9
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/ethereum/go-ethereum@v1.10.26
1.16.9
1
ghcr.io/synapsecns/sanguine/screener-api:latestb3de2050460a
github.com/ethereum/go-ethereum@v1.13.8
1.16.9
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
github.com/ethereum/go-ethereum@v1.10.26
1.16.9
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
github.com/ethereum/go-ethereum@v1.13.8
1.16.9
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
github.com/ethereum/go-ethereum@v1.11.6
1.16.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.