Polygon Discloses Security Flaws Patched by Recent Hard Forks
Polygon has disclosed multiple previously unknown security vulnerabilities in its Bor and Heimdall client nodes, which were patched through two recent hard forks. The flaws include denial-of-service risks, validator resource exhaustion, and defects affecting checkpoint and milestone processing. Polygon stated that these vulnerabilities had been privately tested before being deployed to the mainnet and publicly disclosed.
The most severe issue affects Heimdall, where a carefully crafted transaction could force validators to execute excessive processing work, disrupting the network. The Austin hard fork also patched two denial-of-service risks in Bor that could slow down block processing or cause node crashes. Polygon emphasized that these vulnerabilities had not been exploited on the mainnet and were proactively deployed before detailed information was made public.
Polygon nodes running outdated client versions were disconnected from consensus after the activation of the hard fork height and must be upgraded to rejoin the regular network. All Polygon Proof-of-Stake nodes need to upgrade to Bor v2.1.0, validators and full nodes require Heimdall v0.11.0 upgrades that have taken effect on the mainnet.