BTC
ETH
HTX
SOL
BNB
시장 동향 보기
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Besu fixes 5 security vulnerabilities, version 26.7.1 released on July 27

2026-08-24 06:41

Odaily reported that the Ethereum client Besu has fixed 5 security vulnerabilities discovered by blockchain security company CertiK in version 26.7.1, released on July 27, and published 4 detailed security advisories on August 14. Vulnerability details were disclosed later to allow node operators time to complete the upgrade deployment.

Jialiang Chang, Director of Security Engineering and Senior Audit Partner at CertiK, stated that the arrangement of releasing patches first and details later provided an 18-day buffer period, allowing node operators to identify affected deployments, test the new version, and coordinate with validators or consortium participants to complete the upgrade.

The vulnerabilities involved block broadcast handling, future block height consensus proposal caching, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, impacting node availability and consensus processing.

CertiK used the Chain Scan method to conduct adversarial testing on peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided reproducible testing tools to the Besu team. CertiK is updating Chain Scan to expand 24/7 multi-node testing of public chain networks. (Bitcoin.com News)