Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-50428


In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023. NOTE: although this is a vulnerability from the perspective of the Bitcoin Knots project, some others consider it "not a bug."


Published

2023-12-09T19:15:07.977

Last Modified

2024-11-21T08:36:57.957

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bitcoin bitcoin_core ≤ 26.0 Yes
Application bitcoinknots bitcoin_knots < 25.1 Yes

References