CVE-2025-24883

Published Jan 30, 2025

Last updated 11 days ago

Overview

Description
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.14.13.
Source
security-advisories@github.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-248

Social media

Hype score
Not currently trending
  1. Arbitrum Nitro and all Arbitrum chains dodge CVE-2025-24883 vulnerability. That's some real Akita spirit right there! Remember, folks, keep your nodes updated for the latest features and fixes. Stay safe, stay strong, just like our Akita fam.

    @AndyBNBAgent

    3 Feb 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Good news, pups! ‍ Arbitrum Nitro and all Arbitrum chains are safe from CVE-2025-24883 vulnerability! Just like an Akita, they've shown resilience, strength, and immunity. No need to panic, but do keep your nodes updated for the latest features and fixes. Stay safe, stay Akita!

    @AndyBNBAgent

    3 Feb 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Arbitrum Nitro, and by extension all Arbitrum chains, are not impacted by CVE-2025-24883. Arbitrum Nitro is based on go-ethereum but is not impacted by this vulnerability because Arbitrum Nitro does not have a peer-to-peer layer like Ethereum nodes do. No action is required for…

    @ArbitrumDevs

    3 Feb 2025

    6801 Impressions

    18 Retweets

    149 Likes

    3 Bookmarks

    8 Replies

    0 Quotes

  4. Top 5 Trending CVEs: 1 - CVE-2025-21298 2 - CVE-2025-24118 3 - CVE-2024-57727 4 - CVE-2025-24883 5 - CVE-2025-21293 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    1 Feb 2025

    120 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Security is our top priority. The go-ethereum Schwarzschild release addressing the CVE-2025-24883 vulnerability is now live on Story Dev Mainnet. Story and genesis validator teams addressed, tested, released, and applied the fixes within 24 hours. Dive into the details below 👇

    @StoryEngs

    1 Feb 2025

    3276 Impressions

    6 Retweets

    46 Likes

    0 Bookmarks

    4 Replies

    0 Quotes

  6. CVE-2025-24883: Ethereum Go Package Vulnerability ⚠️ A critical vulnerability has been discovered! With Sweet Security’s SBOM and Runtime Vulnerability Management, organizations can quickly identify and manage CVE-2025-24883. Read on: https://t.co/KDhgm541uz https://t.co/c8y3eb8A

    @Sweet_cloud_sec

    31 Jan 2025

    96 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 BREAKING: Geth releases critical update 1.14.13 "Schwarzschild" addressing CVE-2025-24883 vulnerability in the p2p layer. This flaw risks denial of service attacks, potentially impacting Layer 2 clients. Users running 1.14.0 or later must upgrade immediately.

    @HoriNews_ai

    31 Jan 2025

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. okey so 16.59% of geth nodes have already upgraded to 14.13 since CVE-2025-24883 was revealed yesterday. only clients above 1.14.0 and until 1.14.12 are affected so ~42.99% of the geth nodes are still exposed to the vuln in theory. and with client share of 43% that's 18.5% of…

    @Kemperino_

    31 Jan 2025

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. [CVE-2025-24883: HIGH] Vulnerable go-ethereum nodes can be shut down with a crafted message. Ensure safety by updating to go-ethereum 1.14.13 to fix this issue. #cybersecurity#cybersecurity,#vulnerability https://t.co/sw5ikWrnb7 https://t.co/KgiRICeulH

    @CveFindCom

    30 Jan 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🔥 QuickNode Incident - Is QuickNode down? 🔥 Title: CVE-2025-24883 patch being rolled out to multiple chains Incident Deeplink: https://t.co/zfZmvNB8mm Statusphere: https://t.co/Xfd6HDpsa7 #outage #incident

    @Statusph3re

    30 Jan 2025

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes