HIGH7.5
GHSA-pvx3-gm3c-gmpr
Denial of Service in Go-Ethereum
Details
A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS).
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ethereum/go-ethereum
Introduced in:
0No fixed version published yet for github.com/ethereum/go-ethereum (go modules). Pin to a known-safe version or switch to an alternative.