CVE-2025-46598 - CPU DoS from unconfirmed transaction processing

<p>Disclosure of the details of a resource exhaustion issue when processing an unconfirmed transaction. A fix was released on October 10th 2025 in Bitcoin Core v30.0.</p> <p>This issue is considered <strong>Low</strong> severity.</p> <h2 id="details">Details</h2> <p>An attacker could send specially-crafted unconfirmed transactions that would take a victim node a few seconds each to validate. The non-standard transactions would be rejected but not lead to a disconnection and the process could be repeated. This could be exploited to delay block propagation.</p> <p>The issue was mitigated in multiple steps by reducing the validation time in different Script contexts.</p> <h2 id="attribution">At

Source

Bitcoin Core

A short excerpt in its original language. Read the full story at the source.

Read original source

Copyright (c) 2014 Michael Rose; 2015 Sylvain Durand; 2016 Respective Authors. MIT License. Excerpt. MIT

Comments

No registration required. Your name and comment will be public.

Name: 2–60 characters. Comment: 3–2000 characters. Plain text only. Up to one comment per minute and five per hour.

Loading comments…