Ethereum client Besu patched five security flaws discovered by CertiK in release 26.7.1, shipping July 27 — and published detailed advisories on August 14 after operators had time to upgrade. What happened - Besu, the Java-based Ethereum client, pushed version 26.7.1 as a security-focused update on July 27. The release fixed five vulnerabilities identified by CertiK and addressed additional security issues. Besu’s GitHub release notes credit CertiK and EF Security for responsible disclosure. - Technical advisories describing the CertiK findings were published on August 14, giving node operators access to the patch before public disclosure of the exploit details — a coordinated responsible-disclosure approach. What the flaws were and why they matter - CertiK’s researchers discovered five issues across peer-to-peer, HTTP JSON-RPC, WebSocket RPC, and consensus-facing interfaces. Under certain configurations the flaws could lead to unbounded consumption of memory or threads, risking node availability and even disrupting consensus processing. - Severity ranged from Minor to Major. Specific problem areas included block-announcement processing, buffering of future-height consensus proposals, WebSocket subscription handling, and JSON-RPC filter creation without effective caps. - Two of the key remediations in 26.7.1 add limits for active JSON-RPC filters and WebSocket subscriptions to prevent unbounded resource growth. How the issues were found and fixed - CertiK used its Chain Scan adversarial-testing methodology on a private multi-node Besu testnet, introducing controlled faults across interfaces to surface availability and resource-exhaustion risks. The research was self-directed (not part of a paid engagement). - Researchers provided reproducible proof-of-concept test harnesses to the Besu team. The teams coordinated confidentially while Besu evaluated and patched the code, then published advisories after the fix was available. What node operators should do - Operators running Besu should upgrade to v26.7.1 (or later) if they haven’t already. The release specifically targets the resource-exhaustion vectors and adds practical caps for WebSocket subscriptions and JSON-RPC filters. Context - Besu is an Apache 2.0–licensed, open-source Ethereum client written in Java, used for Mainnet, testnets, and enterprise private networks. It exposes a CLI, JSON-RPC API, and a Plugin API. - CertiK, founded in 2017 by academics from Yale and Columbia, says it has detected more than 119,000 vulnerabilities and helped protect over $600 billion in digital assets across 150+ countries. Note: This content is based on third-party reporting. Neither this platform nor the original author endorses any product; users should perform their own due diligence.
Besu Patches 5 Security Flaws Found by CertiK in Version 26.7.1
ChainGPTShare
Ethereum client Besu released version 26.7.1 on July 27 to fix five security flaws in the layer 1 blockchain client. CertiK found the issues using adversarial testing, affecting peer-to-peer, JSON-RPC, WebSocket, and consensus interfaces. The bugs could cause resource exhaustion and node downtime. Besu added limits to JSON-RPC filters and WebSocket subscriptions to reduce risks. Technical details were shared on August 14. Node operators are urged to upgrade to v26.7.1 or newer for better contract security.
Source:Show original
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information.
Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.