-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from two key issues: 1) The Logs resolver performs unbounded block history processing when 'fromBlock' is used, and 2) The GraphQL handler allows unlimited aliased operations in single requests. Together they enable memory exhaustion via crafted queries. The vendor's documentation confirms GraphQL wasn't designed to handle hostile clients, and the exploit demonstrates how aliased logs queries trigger OOM conditions. These functions are core to GraphQL request processing in Geth's implementation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/ethereum/go-ethereum | go | <= 1.13.4 |
Ongoing coverage of React2Shell