- Besu disclosed five security vulnerabilities identified by CertiK and fixed in version 26.7.1.
- The update added limits for JSON-RPC filters and WebSocket subscriptions.
Ethereum client Besu has disclosed details of five security vulnerabilities identified by blockchain security firm CertiK, all of which were fixed in version 26.7.1 released on July 27. Besu is an open-source Ethereum execution client used on public and private networks.
The issues ranged from Minor to Major severity and were addressed before their technical details were made public on August 14. Besu urged node operators to upgrade to the patched version, giving them time to update their systems before the vulnerabilities were disclosed.
Besu published four security advisories covering the five findings. The vulnerabilities involved block-announcement processing, future-height consensus proposal buffering, WebSocket subscriptions and JSON-RPC filter creation. Under certain configurations, the issues could exhaust node memory or thread capacity, potentially affecting node availability or consensus processing.
Besu Adds New Controls in Version 26.7.1
The vulnerabilities were identified through CertiK’s independent research using its Chain Scan adversarial-testing methodology. Researchers tested Besu on a private, multi-node network and introduced controlled faults across peer-to-peer, HTTP RPC, WebSocket RPC and consensus-facing interfaces while assessing availability and resource-exhaustion risks.
The 26.7.1 release introduced new controls related to two of the affected areas. Besu added a configurable maximum for active JSON-RPC filters and a configurable filter timeout, along with a limit on active WebSocket subscriptions. The release notes also credited CertiK and EF Security for responsible disclosures.
Besu’s advisories now provide operators and developers with public details of the five findings and their remediation. Version 26.7.1 remains the patched release for the vulnerabilities identified by CertiK.
thenewscrypto.com