Besu fixes five security flaws in version 26.7.1 after findings by CertiK

Besu fixes five security flaws in version 26.7.1 after findings by CertiK

N
News Editor
2026-08-24 06:41:16
Ethereum client Besu fixed five security vulnerabilities in version 26.7.1, which was released on July 27, after the issues were identified by blockchain security firm CertiK. Besu then published four detailed security advisories on Aug. 14, with technical details held back until after the patch rollout so node operators had time to upgrade first. According to CertiK Security Engineering Director and Senior Audit Partner Jialiang Chang, that patch-first approach created an 18-day buffer for operators to identify affected deployments, test the new release, and coordinate upgrades with validators or consortium participants. The disclosed issues touched block propagation handling, future-height consensus proposal caching, WebSocket subscription limits, and JSON-RPC filter creation. If left unresolved, the flaws could let attackers drain node memory or thread resources, affecting node availability and consensus processing. Bitcoin.com News said CertiK used its Chain Scan method in a private multi-node test network to run adversarial testing across peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces, and provided reproducible testing tools to the Besu team.

Ethereum client Besu fixed five security vulnerabilities in version 26.7.1, released on July 27, after the issues were identified by blockchain security firm CertiK. On Aug. 14, Besu published four detailed security advisories.

Technical details were disclosed later

The vulnerability details were not released at the same time as the patch. Instead, disclosure was delayed so node operators could complete their upgrades first.

CertiK Security Engineering Director and Senior Audit Partner Jialiang Chang said the patch-first, details-later approach gave node operators an 18-day buffer to identify affected deployments, test the new version, and coordinate upgrades with validators or consortium participants.

Issues touched block propagation and RPC interfaces

The vulnerabilities involved block propagation handling, future-height consensus proposal caching, WebSocket subscription limits, and JSON-RPC filter creation. If they had not been fixed, attackers could have exhausted node memory or thread resources, affecting node availability and consensus processing.

How CertiK tested Besu

According to Bitcoin.com News, CertiK used its Chain Scan method in a private multi-node test network to conduct adversarial testing across peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces. The firm also provided reproducible testing tools to the Besu team.

CertiK said it is updating Chain Scan to expand round-the-clock multi-node testing for public blockchain networks.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.