Besu fixed five vulnerabilities identified by CertiK in version 26.7.1, released July 27, before publishing detailed advisories on August 14. The flaws affected peer-to-peer networking, HTTP RPC, WebSocket RPC and consensus-facing interfaces, where certain configurations could exhaust memory or thread capacity and disrupt node availability or consensus processing. CertiK found the issues through independent testing on a private, multi-node Besu network and supplied reproducible proof-of-concept harnesses. The release added limits for active JSON-RPC filters and WebSocket subscriptions, among other security fixes. Besu credited CertiK and EF Security for responsible disclosure.