BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Besu Releases Security Advisory Disclosing 5 Fixed Vulnerabilities, Thanks CertiK for Responsible Disclosure

2026-08-22 01:40

Odaily News - Recently, Besu published four security advisories disclosing five vulnerabilities discovered by CertiK and their remediation status. All related vulnerabilities have been fixed in Besu version 26.7.1, released on July 27, with technical details officially disclosed on August 14.

The vulnerabilities involve block announcement processing, caching of future block height consensus proposals, WebSocket subscription limits, and unbounded JSON-RPC filter creation. Under specific configurations, attackers could exploit these issues to continuously consume node memory or thread resources, impacting node availability or consensus processing.

These vulnerabilities were identified during CertiK's self-initiated Chain Scan adversarial research, conducted on a private multi-node Besu test network without client commission or commercial involvement. CertiK subsequently submitted all vulnerabilities along with a reproducible proof-of-concept testing framework to Besu, maintaining confidential coordination with them until the patched version was released. Besu expressed gratitude to CertiK and EF Security for their responsible disclosure in the release notes.