logo

Inside CertiK's Independent Security Research on Besu

ID: 6a48d2f5-68c7-5a5e-9313-d7e1b9c58c6f

STIX ID: report--6a48d2f5-68c7-5a5e-9313-d7e1b9c58c6f

Feed Name: CertiK Blog

Threat Score
70/100

Date Published: 2026-08-21

Date Updated: 2026-08-25

...
...

CertiK used a chaos-engineering adversarial testnet to find five resource-exhaustion (denial-of-service) vulnerabilities in the Besu Ethereum client—two Major—that allowed unprivileged peers or JSON-RPC/WebSocket clients to trigger unbounded thread or memory growth, crash nodes, or stall consensus; Besu released fixes in version 26.7.1 and published advisories after coordinated disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.