Besu has disclosed five security vulnerabilities identified by CertiK after fixing them in version 26.7.1, which was released on 27 July as a security update.
The Java-based Ethereum client published detailed advisories on 14 August, several weeks after the patched version became available. The timing allowed Besu operators to upgrade before technical information about the weaknesses was made public.
The vulnerabilities affected peer-to-peer, HTTP JSON-RPC, WebSocket RPC and consensus-facing interfaces. In certain configurations, they could exhaust a node’s memory or available threads, potentially affecting its availability or interfering with consensus processing.
CertiK discovered the issues through independent research conducted on a private, multi-node Besu network. The security firm reported all five findings confidentially to the Besu team and supplied reproducible proof-of-concept test harnesses to help developers investigate the problems.
Besu released version 26.7.1 on 27 July and advised users to install it. The update addressed all five CertiK findings, alongside other security issues. Its GitHub release page describes the version as security-focused and credits CertiK and EF Security for responsible disclosure.
The release notes also introduced new restrictions for JSON-RPC filters and WebSocket subscriptions. Those changes were intended to prevent unrestricted growth in resource use.
Technical details of the CertiK findings were made public on 14 August through four Besu advisories covering the five vulnerabilities. Each advisory listed version 26.7.1 as the release containing the fix.
CertiK said the issues were found using its Chain Scan adversarial-testing methodology. Researchers used a private Besu test network with several nodes and introduced controlled faults across the client’s peer-to-peer, HTTP RPC, WebSocket RPC and consensus-related interfaces.
The testing focused on availability and resource-exhaustion risks under controlled conditions and was not carried out as part of a commercial client engagement. CertiK rated the five findings between Minor and Major in severity.
The affected areas included block-announcement handling, the buffering of consensus proposals from future heights, WebSocket subscription limits and the creation of JSON-RPC filters without effective caps. These functions influence how Besu processes network messages, remote requests, subscriptions and consensus data.
Two of the measures visible in version 26.7.1 place limits on active JSON-RPC filters and WebSocket subscriptions. Besu said those controls close routes that could otherwise allow resources to grow without clear limits.
The project published the advisories only after the patched release was available, following a coordinated responsible-disclosure process. Besu’s release notes acknowledge CertiK and EF Security for their respective disclosures.
Besu is an open-source Ethereum client written in Java and licensed under Apache 2.0, according to Linux Foundation Decentralized Trust. It can be used on public and private networks, serving as an execution client on Ethereum Mainnet and testnets as well as supporting enterprise blockchain deployments.
The software includes a command-line interface, a JSON-RPC API and a Plugin API for node management and extensions.
CertiK was founded in 2017 by professors from Yale University and Columbia University. The company says it has identified more than 119,000 vulnerabilities and helped protect more than $600bn in digital assets across more than 150 countries and regions.
Disclosure: This content is provided by a third party. Neither crypto.news nor the author of this article endorses any product mentioned on this page. Users should conduct their own research before taking any action related to the company.
