XRP Ledger Releases Update to Fix Manifest Flood Vulnerability
The XRP Ledger (XRPL) has released an update to fix a manifest flood vulnerability that affected some of its nodes on July 31. The security issue, which allowed unknown validator manifests to overwhelm XRPL nodes, has been addressed in version 3.2.1.
The update introduces four new protections to prevent similar incidents: rejecting large validator manifests, limiting incoming batches of manifests, capping manifest data shared with peers, and preventing storage of manifests from more than 100 unknown validator keys.
Developers have also made an important improvement by preventing unwanted data from being written to disk. Node operators are advised to update as soon as possible by installing XRPL 3.2.1, waiting for a few minutes, and restarting the software.