Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-35202


Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called twice for one PartiallyDownloadedBlock instance.


Published

2024-10-10T13:15:14.077

Last Modified

2025-05-22T16:51:01.657

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bitcoin bitcoin_core < 25.0 Yes

References