# CVE-2025-24883

## Summary

- **CVE ID:** CVE-2025-24883
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-248
- **Published:** Jan 30, 2025
- **Last Modified:** Mar 12, 2026

## Description

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. A vulnerable node can be forced to shutdown/crash using a specially crafted message. This vulnerability is fixed in 1.14.13.

## Affected Products

- ethereum — go-ethereum (>= 1.14.0, < 1.14.13)

## References

- [CNA](https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2)
- [CNA](https://github.com/ethereum/go-ethereum/commit/fa9a2ff8687ec9efe57b4b9833d5590d20f8a83f)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.69%
- **EPSS Percentile:** 50.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._