<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Bitcoin Core</title>
  <link>https://cvedaily.com/pages/tags/bitcoin-core.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/bitcoin-core.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Bitcoin Core</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-52911 – Bitcoin Core through 28.x has a security issue, the details of which are not dis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52911</guid>
    <pubDate>Tue, 05 May 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52911</strong></p>
  <p>Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46597 – Bitcoin Core 0.13.0 through 29.x has an integer overflow.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46597</guid>
    <pubDate>Fri, 20 Mar 2026 16:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46597</strong></p>
  <p>Bitcoin Core 0.13.0 through 29.x has an integer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-46598 – Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46598</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46598</guid>
    <pubDate>Fri, 20 Mar 2026 15:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-46598</strong></p>
  <p>Bitcoin Core through 29.0 allows a denial of service via a crafted transaction.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-405</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46598">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54605 – Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54605</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54605</guid>
    <pubDate>Tue, 28 Oct 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54605</strong></p>
  <p>Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54605">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54604 – Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54604</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54604</guid>
    <pubDate>Tue, 28 Oct 2025 17:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54604</strong></p>
  <p>Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54604">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55563 – Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain prot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55563</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55563</guid>
    <pubDate>Mon, 09 Dec 2024 01:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55563</strong></p>
  <p>Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timelock Contract) can be changed because a flood of transaction traffic prevents propagation of certain Lightning channel transactions.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55563">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52922 – In Bitcoin Core before 25.1, an attacker can cause a node to not download the la...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52922</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52922</strong></p>
  <p>In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when an announcing peer stalls instead of complying with the peer-to-peer protocol specification.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52921 – In Bitcoin Core before 25.0, a peer can affect the download state of other peers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52921</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52921</strong></p>
  <p>In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52920 – Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52920</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52920</strong></p>
  <p>Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52919 – Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52919</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52919</strong></p>
  <p>Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52918 – Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a deni...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52918</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52918</strong></p>
  <p>Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter for a URL that has a large file.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52917 – Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52917</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52917</strong></p>
  <p>Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52916 – Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon proc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52916</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52916</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52916</strong></p>
  <p>Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52916">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52915 – Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52915</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52915</strong></p>
  <p>Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52914 – In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52914</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52914</strong></p>
  <p>In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-52913 – In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a sp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52913</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-52913</strong></p>
  <p>In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52912 – Bitcoin Core before 0.21.0 allows a network split that is resultant from an inte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52912</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52912</strong></p>
  <p>Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an abs64 logic bug.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25220 – Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25220</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25220</strong></p>
  <p>Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work before committing to store it.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-20111 – miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-20111</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-20111</guid>
    <pubDate>Mon, 18 Nov 2024 04:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-20111</strong></p>
  <p>miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-20111">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38365 – btcd is an alternative full node bitcoin implementation written in Go (golang). ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38365</guid>
    <pubDate>Fri, 11 Oct 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38365</strong></p>
  <p>btcd is an alternative full node bitcoin implementation written in Go (golang). The btcd Bitcoin client (versions 0.10 to 0.24) did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality. This logic is consensus-critical: the difference in behavior with the other Bitcoin clients can lead to btcd clients accepting an invalid Bitcoin block (or rejecting a valid one). This consens…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38365">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35202 – Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35202</guid>
    <pubDate>Thu, 10 Oct 2024 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35202</strong></p>
  <p>Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called twice for one PartiallyDownloadedBlock instance.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-34149 – In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34149</guid>
    <pubDate>Tue, 30 Apr 2024 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-34149</strong></p>
  <p>In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscript lacks a policy size limit check, a different issue than CVE-2023-50428. NOTE: some parties oppose this new limit check (for example, because they agree with the objective but disagree with the technical mechanism, or because they have a different objective).</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-50428 – In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, dataca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50428</guid>
    <pubDate>Sat, 09 Dec 2023 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-50428</strong></p>
  <p>In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023. NOTE: although this is a vulnerability from the perspective of the Bitcoin Knots project, some others consider it "not a bug."</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-37192 – Memory management and protection issues in Bitcoin Core v22 allows attackers to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37192</guid>
    <pubDate>Fri, 07 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-37192</strong></p>
  <p>Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33297 – Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33297</guid>
    <pubDate>Mon, 22 May 2023 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33297</strong></p>
  <p>Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-31876 – Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31876</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31876</guid>
    <pubDate>Thu, 13 May 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-31876</strong></p>
  <p>Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with nSequence = 0xff_ff_ff_ff, spending an unconfirmed parent with nSequence <= 0xff_ff_ff_fd, should b…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31876">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-3401 – Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary cod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3401</guid>
    <pubDate>Thu, 04 Feb 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-3401</strong></p>
  <p>Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt program, as demonstrated by an x-scheme-handler/bitcoin handler for a .desktop file or a web browser. NOTE: the discoverer states "I believe that this vulnerability cannot actually be exploited."</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-88</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3195 – bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3195</guid>
    <pubDate>Tue, 26 Jan 2021 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3195</strong></p>
  <p>bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOTE: this reportedly does not violate the security model of Bitcoin Core, but can violate the security model of a fork that has implemented dumpwallet restrictions</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14198 – Bitcoin Core 0.20.0 allows remote denial of service.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14198</guid>
    <pubDate>Thu, 10 Sep 2020 17:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14198</strong></p>
  <p>Bitcoin Core 0.20.0 allows remote denial of service.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-17145 – Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17145</guid>
    <pubDate>Thu, 10 Sep 2020 17:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-17145</strong></p>
  <p>Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-12842 – Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12842</guid>
    <pubDate>Mon, 16 Mar 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-12842</strong></p>
  <p>Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur. Completing the attack would cost more than a million dollars, and is relevant mainly only in situations where an autonomous system relies solely on an SPV proof for transactions of a greater dollar amount.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15947 – In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15947</guid>
    <pubDate>Thu, 05 Sep 2019 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15947</strong></p>
  <p>In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their private keys, via a grep "6231 0500" command.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-20587 – Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20587</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20587</guid>
    <pubDate>Mon, 11 Feb 2019 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-20587</strong></p>
  <p>Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20587">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-17144 – Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17144</guid>
    <pubDate>Wed, 19 Sep 2018 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-17144</strong></p>
  <p>Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10725 – In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10725</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10725</guid>
    <pubDate>Thu, 05 Jul 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10725</strong></p>
  <p>In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts) because operations occur in the wrong order. This behavior occurs in the remote network alert system (deprecated since Q1 2016). This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10725">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10724 – Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) trigger...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10724</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10724</guid>
    <pubDate>Thu, 05 Jul 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10724</strong></p>
  <p>Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized map. This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10724">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
