Ethereum2026-08-24 06:41:16Besu fixes five security flaws in version 26.7.1 after findings by CertiKEthereum client Besu fixed five security vulnerabilities in version 26.7.1, which was released on July 27, after the issues were identified by blockchain security firm CertiK. Besu then published four detailed security advisories on Aug. 14, with technical details held back until after the patch rollout so node operators had time to upgrade first. According to CertiK Security Engineering Director and Senior Audit Partner Jialiang Chang, that patch-first approach created an 18-day buffer for operators to identify affected deployments, test the new release, and coordinate upgrades with validators or consortium participants. The disclosed issues touched block propagation handling, future-height consensus proposal caching, WebSocket subscription limits, and JSON-RPC filter creation. If left unresolved, the flaws could let attackers drain node memory or thread resources, affecting node availability and consensus processing. Bitcoin.com News said CertiK used its Chain Scan method in a private multi-node test network to run adversarial testing across peer-to-peer, HTTP RPC, WebSocket RPC, and consensus interfaces, and provided reproducible testing tools to the Besu team.1120
Besu2026-08-22 01:40:09Besu Discloses Five Fixed Vulnerabilities, Thanks CertiK for Responsible DisclosureBesu has published four security notices covering five vulnerabilities that CertiK identified and reported. The issues were fixed in Besu 26.7.1, released on July 27, and the technical details were made public on August 14. The bugs affected block announcement handling, caching for future block height consensus proposals, WebSocket subscription limits, and unbounded JSON-RPC filter creation. Besu said the flaws could, under specific configurations, let an attacker keep consuming memory or thread resources and affect node availability or consensus processing. CertiK found the issues through its Chain Scan adversarial research on a private multi-node Besu test network, submitted the vulnerabilities with reproducible proof-of-concept test frameworks, and coordinated confidentially with Besu before the fix was released. Besu thanked CertiK and EF Security in the release notes for responsible disclosure.1370