<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T13:26:26.202457+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-46003</id>
    <title>EUVD-2026-46003</title>
    <updated>2026-10-05T13:26:26.271529+00:00</updated>
    <content>EUVD-2026-46003</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-46003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26265</id>
    <title>fkie_cve-2020-26265</title>
    <updated>2026-10-05T13:26:26.271568+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-26265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xw37-57qp-9mm4</id>
    <title>GHSA-xw37-57qp-9mm4 — Consensus flaw during block processing in github.com/ethereum/go-ethereum</title>
    <updated>2026-10-05T13:26:26.271604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/ethereum/go-ethereum</p>
<p>### Impact</p>
<p>A consensus-vulnerability in Geth could cause a chain split, where vulnerable versions refuse to accept the canonical chain.</p>
<p>### Description</p>
<p>A flaw was repoted at 2020-08-11 by John Youngseok Yang (Software Platform Lab), where a particular sequence of transactions could cause a consensus failure.</p>
<p>- Tx 1:
  - `sender` invokes `caller`.
  - `caller` invokes `0xaa`. `0xaa` has 3 wei, does a self-destruct-to-self
  - `caller` does a  `1 wei` -call to `0xaa`, who thereby has 1 wei (the code in `0xaa` still executed, since the tx is still ongoing, but doesn't redo the selfdestruct, it takes a different path if callvalue is non-zero)</p>
<p>- Tx 2:
  - `sender` does a 5-wei call to 0xaa. No exec (since no code).</p>
<p>In geth, the result would be that `0xaa` had `6 wei`, whereas OE reported (correctly) `5` wei. Furthermore, in geth, if the second tx was not executed, the `0xaa` would be destructed, resulting in `0 wei`. Thus obviously wrong.</p>
<p>It was determined that the root cause was this [commit](https://github.com/ethereum/go-ethereum/commit/223b950944f494a5b4e0957fd9f92c48b09037ad) from [this PR](https://github.com/ethereum/go-ethereum/pull/19953). The semantics of `createObject` was subtly changd, into returning a non-nil object (with `deleted=true`) where it previously did not if the account had been destructed. This return value caused the new object to inherit the old `balance`:</p>
<p>```golang
func (s *StateDB) CreateAccount(addr common.Address) {
	newObj, prev := s.cre…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xw37-57qp-9mm4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-26265</id>
    <title>gsd-2020-26265</title>
    <updated>2026-10-05T13:26:26.271654+00:00</updated>
    <content>gsd-2020-26265</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-26265"/>
  </entry>
</feed>
