Besu patches five CertiK-reported vulnerabilities in July security update

Besu fixed five vulnerabilities identified by CertiK in version 26.7.1, released July 27, before publishing detailed advisories on August 14. The flaws affected peer-to-peer networking, HTTP RPC, WebSocket RPC and consensus-facing interfaces, where certain configurations could exhaust memory or thread capacity and disrupt node availability or consensus processing. CertiK found the issues through independent testing on a private, multi-node Besu network and supplied reproducible proof-of-concept harnesses. The release added limits for active JSON-RPC filters and WebSocket subscriptions, among other security fixes. Besu credited CertiK and EF Security for responsible disclosure.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.