Besu Patches Five Security Flaws Discovered by CertiK

Besu Patches Five Security Flaws Discovered by CertiK

First seen 22 Aug 2026, 10:17 UTC CryptorankKucoin 91% similarity 45.9

Article Content

Browse articles
ThreatCluster

Ethereum client Besu released version 26.7.1 on July 27, 2026, to address five vulnerabilities identified by CertiK. The flaws, which ranged from Minor to Major severity, could lead to unbounded memory or thread consumption, impacting node availability and consensus processing. Technical advisories detailing these vulnerabilities were published on August 14, allowing operators to upgrade before public disclosure. The vulnerabilities were found through CertiK's Chain Scan adversarial-testing methodology on a private multi-node testnet. Key remediations included limits on active JSON-RPC filters and WebSocket subscriptions. Node operators are urged to upgrade to version 26.7.1 or later to mitigate these risks. Besu is an open-source Ethereum client used across various networks.

Key Points: • Besu patched five vulnerabilities identified by CertiK in version 26.7.1. • The vulnerabilities could exhaust node resources, affecting availability and consensus. • Operators are advised to upgrade to the patched version to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
Besu version 26.7.1 released
Besu released a security-focused update fixing five vulnerabilities identified by CertiK.
Kucoin
2026-08-14
Technical advisories published
Besu published detailed advisories on the vulnerabilities, allowing operators to upgrade before public disclosure.
Kucoin
2026-08-22
Articles published on vulnerability disclosure
Both Kucoin and Cryptorank reported on the vulnerabilities and the importance of upgrading to version 26.7.1.
Cryptorank

Community

Browse all →

Tracked Entities in This Story