Home » Besu security vulnerabilities fixed in version 26.7.1

Besu security vulnerabilities fixed in version 26.7.1

by John Paterson



Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.

Besu discloses five CertiK-found flaws after patching them in version 26.7.1, released July 27.

Summary

  • Besu fixed five CertiK-reported vulnerabilities in version 26.7.1 before publishing full technical advisories publicly afterward.
  • CertiK found resource-exhaustion risks across networking, RPC, WebSocket, and consensus interfaces during independent security research.
  • Coordinated disclosure gave Besu operators time to upgrade before detailed vulnerability information became publicly available.

Besu published detailed advisories on August 14 covering five Besu security vulnerabilities found by CertiK and fixed in version 26.7.1, released on July 27.

The issues affected the Java-based Ethereum client across peer-to-peer, RPC, WebSocket, and consensus-facing interfaces. Under affected configurations, they could exhaust memory or thread capacity and disrupt node availability or consensus processing. CertiK found the flaws through self-directed testing on a private, multi-node Besu network and reported them privately to the project team.

Besu 26.7.1 released before technical details

Besu first released version 26.7.1 on July 27 as a security update and urged users to upgrade. The release addressed all five CertiK findings along with separate security issues. Besu’s GitHub release page identifies 26.7.1 as a security-focused update and credits CertiK and EF Security for responsible disclosure. The release notes also introduced limits affecting JSON-RPC filters and WebSocket subscriptions.

Technical details became public on August 14, when Besu published four advisories covering the five CertiK findings. Each advisory identified version 26.7.1 as the patched release. The timing meant operators had access to the fix before detailed information about the weaknesses became public. This coordinated sequence gave users time to upgrade while reducing unnecessary exposure to details before remediation was available.

Coordinated disclosure and independent testing

CertiK reported all five findings directly to the Besu team. Researchers also supplied reproducible proof-of-concept test harnesses that Besu could use to examine the behavior. The two teams coordinated confidentially while Besu evaluated and remediated the issues. They made technical information public only after the patched release was available, following a responsible disclosure process described in the source material.

CertiK identified the Besu security vulnerabilities during self-directed research using its Chain Scan adversarial-testing methodology. The work used a private, multi-node Besu test network. Researchers introduced controlled faults across peer-to-peer, HTTP RPC, WebSocket RPC, and consensus-facing interfaces. They used those tests to examine availability and resource-exhaustion risks under controlled conditions rather than through a client engagement.

Besu security vulnerabilities raised resource risks

The research had no commercial scope. CertiK rated the five findings from Minor to Major in severity. The affected areas included block-announcement processing, buffering of future-height consensus proposals, WebSocket subscription limits, and JSON-RPC filter creation without effective caps. These areas touch how a node handles network messages, subscriptions, remote requests, and consensus-related data.

In affected configurations, the weaknesses could consume node memory or available threads. That resource pressure could interfere with node availability or consensus processing. Two remediations visible in the 26.7.1 release added limits for active JSON-RPC filters and WebSocket subscriptions, closing paths for unbounded resource growth. Besu urged operators to move to the patched version when it released the update.

Advisories add public record of remediation

Besu’s publication of the advisories created a public record of the five findings and their remediation. The project’s release notes also acknowledged CertiK and EF Security for their respective responsible disclosures. Besu is an open-source Ethereum client written in Java and licensed under Apache 2.0, according to Linux Foundation Decentralized Trust. The project supports public and private network use cases.

Besu serves as an execution client on Ethereum Mainnet and testnets, while also supporting enterprise private networks. It provides a command-line interface, JSON-RPC API, and Plugin API for node operations and extensions. CertiK, founded in 2017 by professors from Yale University and Columbia University, says it has detected more than 119,000 vulnerabilities and protected over $600 billion in digital assets across 150+ countries and regions.

Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.



Source link

Related Posts

Leave a Comment