CVE-2023-50428 – Medium Severity Bypass of Data Carrier Size Limit in Bitcoin Core and Bitcoin Knots
Key takeaways
- Severity: Medium (CVSS 5.3)
- Impact: Bypass of datacarrier size limit, enabling large‑payload transactions and potential network spam/DoS.
- Affected: bitcoin_core and bitcoin_knots (all pre‑patch releases).
- Action: Upgrade to the patched releases (Knots 25.1, Bitcoin Core ≥ 25.x) and monitor for OP_FALSE OP_IF patterns.
- Context: The German Federal Office for Information Security (BSI) recently issued updates for multiple Linux kernel DoS flaws, highlighting the broader denial‑of‑service threat landscape.
Overview
CVE-2023-50428 affects the reference implementations of Bitcoin – specifically bitcoin_core and bitcoin_knots. The flaw allows an attacker to bypass the built‑in datacarrier size limit by crafting a script that uses the OP_FALSE OP_IF pattern. This bypass enables arbitrarily large data payloads to be embedded in transactions, which can flood the mempool and degrade network availability (a denial‑of‑service condition).
The vulnerability carries a CVSS 5.3 (Medium) score (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Community reports on Twitter and the VulnSocial signal platform indicate active exploitation attempts as early as March 2026.
In parallel, the German Federal Office for Information Security (BSI) released updates for multiple Linux kernel vulnerabilities that enable denial of service in October 2025. While unrelated to Bitcoin, this underscores the importance of timely patching across the entire software stack.
Technical Details
Bitcoin Core enforces a maximum size for data carried in scripts (the “datacarrier” limit, default 80 bytes). The enforcement occurs in the mempool policy code located in src/kernel/mempool_options.h (see lines 46‑53). By inserting the opcode sequence OP_FALSE OP_IF, an attacker can construct a conditional branch that bypasses the size check, allowing a transaction to carry data far beyond the intended limit.
The issue was first reported in a GitHub issue (ID #29187) and formally assigned CVE‑2023‑50428. A pull request (#28408) introduced a fix that adds explicit validation for the OP_FALSE OP_IF pattern. The fix was merged into Bitcoin Knots 25.1 and back‑ported to Bitcoin Core ≥ 25.x.
Severity & Impact
- CVSS Score: 5.3 (Medium)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Primary Impact: Availability – oversized transactions can saturate the mempool, delaying or dropping legitimate traffic (DoS).
- Secondary Impact: Network health – increased bandwidth consumption and higher CPU/memory usage on full nodes.
Affected Products
- bitcoin_core (all versions prior to the patch)
- bitcoin_knots (all versions prior to the patch)
For a complete list of affected versions, CPE entries, and vendor details, see the official CVE page: https://vulnsocial.com/cve/CVE-2023-50428.
Actionable Insights
- Patch immediately: Upgrade to Bitcoin Knots 25.1 or Bitcoin Core ≥ 25.x, which contain the fix for the OP_FALSE OP_IF bypass. The change is documented in the release notes (see reference).
- Validate your node version: Run the following command to confirm you are on a patched release:
bitcoin-cli getnetworkinfo | grep version - Monitor transaction patterns: Implement logging or RPC filters to flag transactions that contain the
OP_FALSE OP_IFopcode sequence with payloads exceeding the standard datacarrier limit. - Enforce stricter mempool policies: Adjust
maxdatacarriersizeinbitcoin.conf(e.g., set to 80 bytes) and consider custom validation rules to reject oversized data carriers. - Leverage threat intel: Track real‑time signals on the VulnSocial CVE page (https://vulnsocial.com/cve/CVE-2023-50428) for any new exploitation reports or indicator updates.
Remediation & Mitigation
- Patch the software – pull the latest release from the official repository or apply the back‑ported commit from PR #28408.
- Restart the node – after updating, restart the daemon and verify the version using
bitcoin-cli getnetworkinfo. - Configure mempool limits – set
maxdatacarriersizeto a conservative value (e.g., 80 bytes) inbitcoin.conf. - Deploy detection rules – add signatures to IDS/IPS that match the
OP_FALSE OP_IFpattern with large payloads. - Stay informed – subscribe to the VulnSocial CVE feed for ongoing updates and emerging threat indicators.
References
- https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures
- https://github.com/bitcoin/bitcoin/blob/65c05db660b2ca1d0076b0d8573a6760b3228068/src/kernel/mempool_options.h#L46-L53
- https://github.com/bitcoin/bitcoin/pull/28408#issuecomment-1844981799
- https://github.com/bitcoin/bitcoin/tags
- https://github.com/bitcoinknots/bitcoin/blob/aed49ce8989334c364a219a6eb016a3897d4e3d7/doc/release-notes.md
- https://twitter.com/LukeDashjr/status/1732204937466032285
- https://vulnsocial.com/cve/CVE-2023-50428
- https://vulnsocial.com
Bottom line
CVE-2023-50428 is a Medium severity vulnerability that lets attackers bypass Bitcoin’s datacarrier size limit, enabling transaction spam and potential denial‑of‑service attacks. The fix is already available in the latest releases of Bitcoin Core and Bitcoin Knots. Upgrade now, enforce strict mempool policies, and monitor for suspicious OP_FALSE OP_IF transactions to protect your node and the broader network.
#CVE202350428 #Bitcoin #DoS #Medium #vuln-action #vuln-danger
