PT-2025-5350 · Cometbft+1 · Cometbft+1

Published

2025-02-03

·

Updated

2026-04-28

·

CVE-2025-24371

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CometBFT versions prior to 0.38.17 CometBFT versions prior to 1.0.1
Description CometBFT is a distributed, Byzantine fault-tolerant, deterministic state machine replication engine. In the blocksync protocol, peers send their base and latest heights when they connect to a new node, which is syncing to the tip of a network. The existing code doesn't check for the case where a peer first reports a latest height X and immediately after height Y, where X > Y. This condition requires the introduction of malicious code in the full node first reporting a non-existing latest height, then reporting a lower latest height, and nodes that are syncing using the blocksync protocol.
Recommendations For versions prior to 0.38.17, upgrade to version 0.38.17 or later. For versions prior to 1.0.1, upgrade to version 1.0.1 or later. As a temporary workaround, operators may attempt to ban malicious peers from the network.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-24371
GHSA-22QQ-3XWM-R5X4
GO-2025-3442
OPENSUSE-SU-2025:14732-1
OPENSUSE-SU-2025_0429-1
SUSE-SU-2025:0429-1

Affected Products

Cometbft
Suse