Besu Patches Critical Vulnerabilities in Urgent Security Update
The open-source Ethereum client Besu has released an urgent security update to address five vulnerabilities discovered by blockchain security firm Certik. The vulnerabilities were found during self-directed research conducted by Certik using its 'Chain Scan' adversarial-testing methodology, which simulates controlled faults across peer-to-peer, HTTP RPC, WebSocket RPC, and consensus-facing interfaces.
The Besu team remediated the flaws in version 26.7.1, released July 27, but delayed publishing advisory details until August 14 to protect node operators against immediate 'N-day' exploits. According to Jialiang Chang, director of security engineering and senior audit partner at Certik, this approach gives network defenders a critical advantage over potential exploiters.
The disclosure gap reduced immediate exploitation risks while maintaining community transparency. The vulnerabilities were rated by Certik from minor to major in severity, including weaknesses in block-announcement processing, future-height consensus proposal buffering, WebSocket subscription limits, and JSON-RPC filter creation. Left unaddressed, the flaws could allow an attacker to exhaust node memory or thread capacity.