EX
EXBASI.COMLive Crypto Intelligence
⌘K
Back to News

Besu Fixes Five Security Vulnerabilities Discovered by CertiK

By Exbasi Intelligence
Sourced from Binance News
Besu Fixes Five Security Vulnerabilities Discovered by CertiK
Ethereum client Besu fixed five security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1, released on July 27, and published four detailed security advisories on August 14. According to Odaily, disclosure of the vulnerability details was delayed to give node operators time to complete upgrades.CertiK Security Engineering Director and Senior Audit Partner Jialiang Chang said the patch-first, details-later approach provided an 18-day buffer for node operators to identify affected deployments, test the new version, and coordinate upgrades with validators or consortium participants.The vulnerabilities involved block broadcast handling, future-height consensus proposal caching, WebSocket subscription limits, and JSON-RPC filter creation. If left unpatched, attackers could exhaust node memory or thread resources, affecting node availability and consensus processing.CertiK said it used its Chain Scan method to conduct adversarial testing of peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces in a private multi-node test network, and provided Besu with reproducible testing tools. CertiK is updating Chain Scan to expand around-the-clock multi-node testing on public blockchain networks.

AI Market Prediction