XRPL Node Operators Urged to Install Critical Fix Amid Manifest Flood Attack
Ripple's Director of Engineering, Vijay Khanna, has issued an urgent update for XRP Ledger node operators. The recent XRPL release, version 3.2.1, includes a critical fix that prevents the manifest flood attack. This security patch is essential to safeguard the network from potential vulnerabilities.
The manifest flood attack was observed on July 31, and the new xrpld version 3.2.1 contains four key limits: size cap per manifest, receive cap for incoming batches, send cap for bulk manifest greetings, and cache cap for unknown keys. These limits prevent malicious manifests from being accepted, stored, or rebroadcast by nodes.
Khanna advises validators to upgrade to version 3.2.1 as soon as possible by following a three-step process: updating normally to XRPL 3.2.1, confirming xrpld is running, and restarting xrpld again.