Summary
Besu fixed the five vulnerabilities reported by CertiK in version 26.7.1 released on July 27, before releasing a full technical announcement.
CertiK identified resource depletion risks in networks, RPC, WebSocket and consensus interfaces in independent security research.
The coordinated disclosure mechanism gives Besu operators time to upgrade before details of the vulnerability are made public.
Besu released version 26.7.1 to fix the vulnerability, and technical details were later disclosed.
On August 14, Besu released a detailed security bulletin covering the five security vulnerabilities discovered by CertiK. These vulnerabilities were fixed in version 26.7.1 released on July 27. These issues affect the point-to-point, RPC, WebSocket and consensus interfaces of Java-based Ethereum clients. In certain configurations, these vulnerabilities can cause memory or thread capacity depletion, affecting node availability or consensus processing. CertiK discovered these flaws through autonomous testing on a private multi-node Besu network and reported them privately to the project team.
Besu version 26.7.1 released before technical details are released
Besu first released version 26.7.1 as a security update on July 27 and urged users to upgrade. This release fixes all five issues identified by CertiK while also addressing other security issues. Besu's GitHub release page marks 26.7.1 as a security update and thanks CertiK and EF Security for their responsible disclosure. Release notes also introduce restrictions on JSON-RPC filters and WebSocket subscriptions.
The technical details were made public on August 14, when Besu issued four safety bulletins covering five issues identified by CertiK. Each bulletin identifies version 26.7.1 as a repaired version. This timing means operators can obtain fixes before details of the vulnerability are made public. This coordination process gives users time to upgrade while reducing unnecessary exposure of detail before fixes are available.
Coordinate disclosure and independent testing
CertiK reported all five findings directly to the Besu team. The researchers also provided a reproducible proof-of-concept testing tool that Besu could use to analyze behavior. During Besu's assessment and repair of the problem, the teams of both parties coordinated confidentially. They only disclosed technical information after the fix version was released, following the responsible disclosure process described in the source materials.
CertiK used its Chain Scan adversarial testing method to discover these Besu security vulnerabilities in independent research. The study used a private multi-node Besu test network. Researchers introduced controlled failures in point-to-point, HTTP RPC, WebSocket RPC, and consensus interfaces. They use these tests to check availability and resource depletion risks under controlled conditions, rather than delegated by customers.
Besu security vulnerability poses resource risks
The study has no commercial scope. CertiK rated the severity of the five findings as "slight" to "severe." Affected areas include block announcement processing, buffering of future high-consensus proposals, WebSocket subscription restrictions, and JSON-RPC filter creation with no valid upper limit. These areas involve how nodes handle network messages, subscriptions, remote requests, and consensus-related data.
In affected configurations, these weaknesses may consume node memory or available threads. This resource pressure may interfere with node availability or consensus processing. 26.7.1 Two fixes visible in the version add restrictions to active JSON-RPC filters and WebSocket subscriptions, blocking the path of unlimited resource growth. Besu urged operators to upgrade to the repaired version when releasing the update.
Security bulletin leaves public record of fixes
The security bulletin issued by Besu leaves a public record of these five findings and their fixes. The project's release instructions also thanked CertiK and EF Security for their responsible disclosures respectively. According to the Linux Foundation Decentralized Trust, Besu is an open source Ethereum client written in Java and released under the Apache 2.0 license. The project supports public network and Private Cloud usage scenarios.
Besu serves as an execution client for the Ethereum main network and test network, and also supports enterprise Private Cloud. It provides a command-line interface, JSON-RPC API, and plug-in API for node operations and extensions. Founded in 2017 by professors from Yale University and Colombia University, CertiK claims to have detected more than 119,000 vulnerabilities and protected more than US$600 billion in digital assets in more than 150 countries and regions.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following