<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 13:26:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-46003</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-46003</link>
      <description>EUVD-2026-46003</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-46003</guid>
    </item>
    <item>
      <title>fkie_cve-2020-26265</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-26265</link>
      <description>&lt;p&gt;Go Ethereum, or &amp;#34;Geth&amp;#34;, is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Go Ethereum, or &amp;#34;Geth&amp;#34;, is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-26265</guid>
    </item>
    <item>
      <title>GHSA-xw37-57qp-9mm4 — Consensus flaw during block processing in github.com/ethereum/go-ethereum</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xw37-57qp-9mm4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/ethereum/go-ethereum&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A consensus-vulnerability in Geth could cause a chain split, where vulnerable versions refuse to accept the canonical chain.&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;A flaw was repoted at 2020-08-11 by John Youngseok Yang (Software Platform Lab), where a particular sequence of transactions could cause a consensus failure.&lt;/p&gt;
&lt;p&gt;- Tx 1:
  - `sender` invokes `caller`.
  - `caller` invokes `0xaa`. `0xaa` has 3 wei, does a self-destruct-to-self
  - `caller` does a  `1 wei` -call to `0xaa`, who thereby has 1 wei (the code in `0xaa` still executed, since the tx is still ongoing, but doesn&amp;#39;t redo the selfdestruct, it takes a different path if callvalue is non-zero)&lt;/p&gt;
&lt;p&gt;- Tx 2:
  - `sender` does a 5-wei call to 0xaa. No exec (since no code).&lt;/p&gt;
&lt;p&gt;In geth, the result would be that `0xaa` had `6 wei`, whereas OE reported (correctly) `5` wei. Furthermore, in geth, if the second tx was not executed, the `0xaa` would be destructed, resulting in `0 wei`. Thus obviously wrong.&lt;/p&gt;
&lt;p&gt;It was determined that the root cause was this [commit](https://github.com/ethereum/go-ethereum/commit/223b950944f494a5b4e0957fd9f92c48b09037ad) from [this PR](https://github.com/ethereum/go-ethereum/pull/19953). The semantics of `createObject` was subtly changd, into returning a non-nil object (with `deleted=true`) where it previously did not if the account had been destructed. This return value caused the new object to inherit the old `balance`:&lt;/p&gt;
&lt;p&gt;```golang
func (s *StateDB) CreateAccount(addr common.Address) {
	newObj, prev := s.cre…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/ethereum/go-ethereum&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A consensus-vulnerability in Geth could cause a chain split, where vulnerable versions refuse to accept the canonical chain.&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;A flaw was repoted at 2020-08-11 by John Youngseok Yang (Software Platform Lab), where a particular sequence of transactions could cause a consensus failure.&lt;/p&gt;
&lt;p&gt;- Tx 1:
  - `sender` invokes `caller`.
  - `caller` invokes `0xaa`. `0xaa` has 3 wei, does a self-destruct-to-self
  - `caller` does a  `1 wei` -call to `0xaa`, who thereby has 1 wei (the code in `0xaa` still executed, since the tx is still ongoing, but doesn&amp;#39;t redo the selfdestruct, it takes a different path if callvalue is non-zero)&lt;/p&gt;
&lt;p&gt;- Tx 2:
  - `sender` does a 5-wei call to 0xaa. No exec (since no code).&lt;/p&gt;
&lt;p&gt;In geth, the result would be that `0xaa` had `6 wei`, whereas OE reported (correctly) `5` wei. Furthermore, in geth, if the second tx was not executed, the `0xaa` would be destructed, resulting in `0 wei`. Thus obviously wrong.&lt;/p&gt;
&lt;p&gt;It was determined that the root cause was this [commit](https://github.com/ethereum/go-ethereum/commit/223b950944f494a5b4e0957fd9f92c48b09037ad) from [this PR](https://github.com/ethereum/go-ethereum/pull/19953). The semantics of `createObject` was subtly changd, into returning a non-nil object (with `deleted=true`) where it previously did not if the account had been destructed. This return value caused the new object to inherit the old `balance`:&lt;/p&gt;
&lt;p&gt;```golang
func (s *StateDB) CreateAccount(addr common.Address) {
	newObj, prev := s.cre…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xw37-57qp-9mm4</guid>
    </item>
    <item>
      <title>gsd-2020-26265</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-26265</link>
      <description>gsd-2020-26265</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-26265</guid>
    </item>
  </channel>
</rss>
