Besu Patches 5 Vulnerabilities with 'Patch-First' Approach
The open-source Ethereum client Besu has patched five security vulnerabilities that could have allowed an attacker to exhaust node memory or thread capacity, threatening node availability and consensus processing.
The vulnerabilities were discovered by blockchain security firm Certik using its 'Chain Scan' adversarial-testing methodology. The flaws included weaknesses in block-announcement processing, future-height consensus proposal buffering, WebSocket subscription limits, and JSON-RPC filter creation.
Besu published four detailed security advisories on August 14 covering the five vulnerabilities, all of which were resolved in version 26.7.1, originally released July 27 as an urgent security update.
Jialiang Chang, director of security engineering and senior audit partner at Certik, emphasized that 'a patch-first' approach gives network defenders a critical advantage over potential exploiters. This approach allows node operators to prepare for upgrades and reduce immediate exploitation risks while maintaining community transparency.