-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from how fork choice handles timestamp-based difficulty adjustments and tiebreaking. The ReorgNeeded function in forkchoice.go (lines 91-94 referenced in advisories) implements logic where manipulated timestamps could create equal-difficulty scenarios, triggering the vulnerable probabilistic tiebreaker. This matches the described RUM attack vector where timestamp manipulation enables main-chain replacement without risk.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/ethereum/go-ethereum | go | <= 1.10.21 |
Ongoing coverage of React2Shell