Ethereum client Besu fixed five security vulnerabilities identified by blockchain security firm CertiK in version 26.7.1, released on July 27, and later published four detailed security advisories on Aug. 14. The vulnerability details were held back at first to give node operators time to upgrade. CertiK Security Engineering Director and Senior Audit Partner Jialiang Chang said the patch-first approach created an 18-day window for operators to identify affected deployments, test the new release and coordinate upgrades with validators or consortium participants. The issues touched block propagation handling, caching of future-height consensus proposals, WebSocket subscription limits and JSON-RPC filter creation. If left unpatched, an attacker could exhaust node memory or thread resources, affecting node availability and consensus processing. CertiK said it used its Chain Scan method to run adversarial testing against peer-to-peer, HTTP RPC, WebSocket RPC and consensus interfaces in a private multi-node test network, and provided reproducible test tools to the Besu team.
Ethereum client Besu fixed five security vulnerabilities discovered by blockchain security firm CertiK in version 26.7.1, released on July 27. It later issued four detailed security advisories on Aug. 14.
Disclosure was delayed to allow upgrades
The vulnerability details were not disclosed immediately, giving node operators time to complete upgrade deployment. Jialiang Chang, CertiK’s director of security engineering and senior audit partner, said the patch-first and details-later approach created an 18-day buffer. During that period, node operators could identify affected deployments, test the new version and coordinate upgrades with validators or consortium participants.
What the flaws affected
The vulnerabilities involved block propagation handling, caching for future-height consensus proposals, WebSocket subscription limits and JSON-RPC filter creation. If they had not been fixed, an attacker could have exhausted node memory or thread resources, affecting node availability and consensus processing.
How CertiK tested Besu
CertiK said it used its Chain Scan method to conduct adversarial testing in a private multi-node test network across peer-to-peer, HTTP RPC, WebSocket RPC and consensus interfaces. The company also provided reproducible testing tools to the Besu team. CertiK is now updating Chain Scan to expand round-the-clock multi-node testing for public blockchain networks.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.