started · updated
Besu patches five security vulnerabilities identified by CertiK
Besu, an open-source Ethereum execution client, has disclosed details regarding five security vulnerabilities identified by blockchain security firm CertiK. The vulnerabilities, which ranged in severity from minor to major, were addressed in the release of version 26.7.1 on July 27.
The flaws involved block-announcement processing, consensus proposal buffering for future heights, WebSocket subscription limits, and JSON-RPC filter creation. Under specific configurations, these issues could lead to the exhaustion of node memory or thread capacity, potentially impacting node availability or consensus processing.
To mitigate these risks, the 26.7.1 update introduced new controls, including configurable maximums for active JSON-RPC filters and limits on active WebSocket subscriptions. Besu coordinated the disclosure with CertiK and EF Security, allowing node operators time to upgrade to the patched version before the technical details were made public on August 14.
Entities
Besu · CertiK · EF Security · Ethereum