PT-2024-36556 · Unknown · Bitcoin Core

Antoine Riard

·

Published

2024-12-09

·

Updated

2025-10-23

·

CVE-2024-55563

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Bitcoin Core versions prior to 27.3
Description The issue allows for transaction-relay jamming via an off-chain protocol attack. This can change the outcome of an HTLC (Hashed Timelock Contract) because a flood of transaction traffic prevents propagation of certain Lightning channel transactions. The vulnerability poses a threat to the Bitcoin Lightning Network, potentially disrupting transactions and leading to financial losses.
Recommendations For Bitcoin Core versions prior to 27.3, update to version 27.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of HTLCs until a patch is applied. Avoid using the transaction-relay feature in the affected Bitcoin Core versions until the issue is resolved.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55563

Affected Products

Bitcoin Core