Bitcoin / Bitcoin Core
56 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-46598 | Bitcoin Core through 29.0 allows a denial of service via a crafted transaction. | MEDIUM | 5.3 | Mar 20, 2026 |
| CVE-2025-46597 | Bitcoin Core 0.13.0 through 29.x has an integer overflow. | HIGH | 7.5 | Mar 20, 2026 |
| CVE-2025-54605 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 2 of 2). | HIGH | 7.5 | Oct 28, 2025 |
| CVE-2025-54604 | Bitcoin Core through 29.0 allows Uncontrolled Resource Consumption (issue 1 of 2). | HIGH | 7.5 | Oct 28, 2025 |
| CVE-2024-55563 | Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an… | MEDIUM | 5.3 | Dec 9, 2024 |
| CVE-2024-52922 | In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when an announcing peer stall… | MEDIUM | 6.5 | Nov 18, 2024 |
| CVE-2024-52921 | In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block. | MEDIUM | 5.3 | Nov 18, 2024 |
| CVE-2024-52920 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message. | HIGH | 7.5 | Nov 18, 2024 |
| CVE-2024-52919 | Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages. | MEDIUM | 6.5 | Nov 18, 2024 |
| CVE-2024-52918 | Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r paramete… | MEDIUM | 6.5 | Nov 18, 2024 |
| CVE-2024-52917 | Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH… | MEDIUM | 6.5 | Nov 18, 2024 |
| CVE-2024-52916 | Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers. | HIGH | 7.5 | Nov 18, 2024 |
| CVE-2024-52915 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message. | HIGH | 7.5 | Nov 18, 2024 |
| CVE-2024-52914 | In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction. | HIGH | 7.5 | Nov 18, 2024 |
| CVE-2024-52913 | In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled. | MEDIUM | 5.3 | Nov 18, 2024 |
| CVE-2024-52912 | Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an ab… | HIGH | 7.5 | Nov 18, 2024 |
| CVE-2019-25220 | Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width… | HIGH | 7.5 | Nov 18, 2024 |
| CVE-2015-20111 | miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and sign… | CRITICAL | 9.8 | Nov 18, 2024 |
| CVE-2024-35202 | Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in… | HIGH | 7.5 | Oct 10, 2024 |
| CVE-2023-50428 | In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FA… | MEDIUM | 5.3 | Dec 9, 2023 |
| CVE-2023-37192 | Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing… | HIGH | 7.5 | Jul 6, 2023 |
| CVE-2023-33297 | Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-… | HIGH | 7.5 | May 22, 2023 |
| CVE-2021-3195 | bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOT… | HIGH | 7.5 | Jan 21, 2021 |
| CVE-2020-14198 | Bitcoin Core 0.20.0 allows remote denial of service. | HIGH | 7.5 | Sep 10, 2020 |
| CVE-2018-17145 | Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with r… | HIGH | 7.5 | Sep 10, 2020 |
Showing 1 to 25 of 56 CVEs