CVE-2024-34149General

LOWCVSS 6.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscript lacks a policy size limit check, a different issue than CVE-2023-50428. NOTE: some parties oppose this new limit check (for example, because they agree with the objective but disagree with the technical mechanism, or because they have a different objective).

1.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 23 mentions across 17 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 4 signals
  • General: 16 classified signals
  • Disclosure: 1 classified signal
  • Peaked 10d ago at 3 mentions (2026-03-01); latest day: 2
  • 23 total mentions across 17 days

Deep dive

Activity timeline23 mentions / 17d
01223Mentions · 2026-02-13: 1Mentions · 2026-02-22: 2Mentions · 2026-02-24: 2Mentions · 2026-02-25: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 3Mentions · 2026-03-04: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-03-24: 1Mentions · 2026-03-26: 1Mentions · 2026-06-15: 1Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-07-14: 2Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-07-14: 2Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-07-14: 202-1302-2202-2402-2502-2702-2803-0103-0403-0603-1003-1103-2403-2606-1507-1007-1107-14
Signal classification4 categories
General
1669.6%
Patch
521.7%
Disclosure
14.3%
False Positive
14.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-131
Patch1
2026-02-222
General2
2026-02-242
Disclosure1General1
2026-02-251
Patch1
2026-02-271
General1
2026-02-281
General1
2026-03-013
General2Patch1
2026-03-041
General1
2026-03-061
General1
2026-03-101
General1
2026-03-112
General2
2026-03-241
General1
2026-03-261
General1
2026-06-151
Patch1
2026-07-101
False Positive1
2026-07-111
General1
2026-07-142
General1Patch1
Full discourse20 posts
  • Luke de Wolf@lukedewolf
    Patch

    There are two specific vulnerabilities in Bitcoin Core that could have been fixed and avoided any talk of a fork. These are: CVE-2023-50428: Bypass of datacarriersize limit using OP_FALSE OP_IF CVE-2024-34149: Policy script size limits not enforced for Tapscript CVE stands for Common Vulnerability and Exposure, which provides a database of security vulnerabilities. The issues allowing spam to propagate freely on Bitcoin were acknowledged as vulnerabilities and made it into the CVE database. From a cybersecurity perspective, fixing vulnerabilities is a no brainer, even if the effect of the fix isn't perfect. Basic code changes would have at least made it so that the latest versions of Core and onward would not have that specific bug. The issues were fixed in Knots 25.1. Varying rationale has been given for not implementing the proposed fixes, but to me, all that has happened is that two bugs weren't fixed. I don't care that spammers would have an alternate method of getting their transactions relayed. The official policy of the reference implementation would be that relaying those transactions is non-standard. Policy defaults matter. Standards matter. Friction matters. This whole problem could have been solved ages ago by Core practicing basic vulnerability management.

    Post summary

    The post highlights two Bitcoin Core CVEs, notes they were fixed in Knots 25.1, and criticizes the lack of earlier patching, emphasizing the importance of timely vulnerability management.

    134551961618.4K
    3.6K followersView on X
  • ANTON@Anton__BTC
    General

    Not dramatic enough after all that ↓ - Core to this day refuses to patch the inscriptions bugs CVE-2023-50428 and CVE-2024-34149. - Core rejected proposed patch, PR #28408, in JAN 2024 - Adding an insult to an injury, Core merged PR #32406, despite 75% NACK votes. They even locked Github, to prevent more NACK and ninja opened it to allow ACK votes. BIP110 is a proper response to all that. Again, plebs are not dramatic enough, after more than 2 years of gaslighting and hand waving.

    Post summary

    The post criticizes Core for refusing to patch CVE-2023-50428 and CVE-2024-34149, rejecting proposed fixes and merging a controversial PR, but it offers no evidence of exploitation, PoC, or mitigation.

    21728151.2K
    9.9K followersView on X
  • Luke Dashjr@LukeDashjr
    Disclosure

    @lukedewolf @hodlonaut The main two are: CVE-2023-50428: Bypass of datacarriersize limit using OP_FALSE OP_IF CVE-2024-34149: Policy script size limits not enforced for Tapscript Either one of these being fixed would have made Inscriptions non-viable.

    Post summary

    The tweet lists two CVEs with technical details about bypassing Bitcoin script limits, noting that fixing either would have made Inscriptions non‑viable.

    5151756750
    103.5K followersView on X
  • Axexang@axexang
    General

    @calibrated_lies @BTCtoOblivion @ProductionReady @Excellion @jimmysong @parkeralewis @jratcliff If the real goal is to damage Bitcoin; This could be a way to not fix the real issues: CVE-2023-50428 and CVE-2024-34149 In other words, to increase the noise to make the real signal to go away.

    Post summary

    The user merely references two CVEs without providing any exploitation details, patches, or technical information.

    11060148
    1.2K followersView on X
  • ANTON@Anton__BTC
    General

    FrickFracck, thing were fine until 2023 when ordinals happened. - Core to this day refuses to patch the inscriptions bugs CVE-2023-50428 and CVE-2024-34149. - Adding an insult to an injury, Core merged PR #32406, despite 75% NACK votes. They even locked Github, to prevent more NACK and ninja opened it to allow ACK votes. BIP110 is a proper response to all that.

    Post summary

    The post notes that Core has not patched CVE-2023-50428 and CVE-2024-34149 and references a controversial PR merge, but provides no technical or exploit details.

    00030154
    9.9K followersView on X
  • ANTON@Anton__BTC
    Patch

    Leurico, that's an utter BS. It's been going on since 2023. Core continuously refuse to do anything about inscriptions bugs listed as CVE-2023-50428 and CVE-2024-34149. Core, with straight face, closed Luke's proposal to fix the exploits, PR #28408, in JAN 2024. Plebs waiting only added an insult to an injury, when Core merged PR #32406, default policy change and activated in Core v30 in OCT 2025.

    Post summary

    The post criticizes Core for not addressing CVE-2023-50428 and CVE-2024-34149, but notes that a policy‑change patch (PR #32406) was merged and activated in Core v30.

    10020127
    9.9K followersView on X
  • Axexang@axexang
    General

    @Degen_chi @BTCtoOblivion @SGBarbour Did the maintainers at "core" did the work we expected them to do and implement the fix for: CVE-2023-50428 and CVE-2024-34149?

    Post summary

    The tweet merely asks whether maintainers have applied fixes for CVE‑2023‑50428 and CVE‑2024‑34149, without providing additional technical or status information.

    1001067
    1.2K followersView on X
  • Axexang@axexang
    General

    @dadrabbot @GrassFedBitcoin Could explain to us why the CVEs below are not fixed? CVE-2023-50428 CVE-2024-34149

    Post summary

    The post is a simple inquiry asking why CVE-2023-50428 and CVE-2024-34149 are not fixed, without providing or linking to any additional information.

    0001036
    1.2K followersView on X
  • Michael Rozman@michael_rozman
    False Positive

    @axexang @stephanlivera CVE-2023-50428 and CVE-2024-34149 are not an issue for the network or for me as a node operator who cares about efficiency and savings. This is just a fact, but it's really hard to argue with extremely stupid people who are also non technical.

    Post summary

    The user argues that CVE-2023-50428 and CVE-2024-34149 do not affect their setup, making a debunking claim without providing technical evidence or mitigation details.

    1000053
    48 followersView on X
  • Mateus Lopes@MateusLopes
    General

    @axexang @BtcLiberty @notgrubles @NickSzabo4 @_bholm @Rombbb_Gaming @asanoha_gold I see! Thanks for the references. Both CVEs you mention are not about Mempool UTXOs living on the RAM. People can read them here: https://nvd.nist.gov/vuln/detail/CVE-2024-34149 (AWAITING ANALYSIS) https://nvd.nist.gov/vuln/detail/CVE-2023-50428 (...some consider it "not a bug."...)

    Post summary

    The tweet cites two CVEs and points to their NVD pages but does not provide any exploitation details, patches, or technical information.

    10000124
    974 followersView on X
  • Axexang@axexang
    General

    @brt2412 @Krev2323 @w_s_bitcoin It is junk because it adds a negative monetary value to the Bitcoin network. It is only possible because "core" refused to fix major security issues: CVE-2023-50428 and CVE-2024-34149

    Post summary

    The comment references CVE‑2023‑50428 and CVE‑2024‑34149, lamenting that Bitcoin core did not address them, but provides no technical or actionable details.

    1000047
    1.2K followersView on X
  • Axexang@axexang
    General

    @Krev2323 @brt2412 @w_s_bitcoin Rug the sc@mmers! This world does not one more sh|tcoin, and the BIP will be enabled. Are you really thinking that Bitcoiners are too dumb to not fix major security issues (CVE-2023-50428, CVE-2024-34149...)?

    Post summary

    The tweet merely references two CVE identifiers without providing any technical details, proof‑of‑concepts, exploit code, or patch information.

    1000034
    1.2K followersView on X
  • Axexang@axexang
    General

    @_jfrader @BTC_for_Freedom This is not a "little spam"; Bitcoin is not a database, and this junk has a direct impact on the RAM usage of a node. This attack is possible because two CVEs were not fixed: CVE-2023-50428 and CVE-2024-34149; "core" is directly responsible for this!

    Post summary

    The tweet references two unfixed CVEs that allegedly impact Bitcoin node memory usage but provides no evidence of exploitation, PoC, or fixes.

    1000089
    1.2K followersView on X
  • Axexang@axexang
    General

    @Vorstand1 @notgrubles Which is only possible because of CVEs (CVE-2023-50428, CVE-2024-34149) which where not fixed. Not fixing a CVE is more than incompetence.

    Post summary

    The tweet references two CVEs that remain unfixed, highlighting a lack of remediation but providing no further technical or exploit details.

    1000091
    1.1K followersView on X
  • Axexang@axexang
    General

    @baclfoo @GrassFedBitcoin @BTCsessions Indeed, but not at this rate which is not in line with the hardware improvements. This is a consequence of CVE-2023-50428 and CVE-2024-34149 which are major security issues.

    Post summary

    The user references CVE-2023-50428 and CVE-2024-34149 as major security issues but provides no further details or actionable information.

    10000123
    1.1K followersView on X
  • Axexang@axexang
    Patch

    @jturner @BitcoinUndisc @notgrubles @theonevortex The gentleman agreement we had was to use "filters" at the mempool level (before CVE-2023-50428 and CVE-2024-34149) to remove the junk which is harmful to Bitcoin. "Core" found a way to not fixes these CVEs (gazlighting…).

    Post summary

    The message references two CVEs and notes a mempool-level filter workaround, indicating that the core team has chosen not to patch the vulnerabilities directly.

    10000162
    1.1K followersView on X
  • Ziopat@PatriceinMilano
    General

    Luke de Wolf highlighted two CVEs in Bitcoin Core (CVE-2023-50428 and CVE-2024-34149) that were never fixed in Core but were addressed in Knots 25.1. Both relate to policy limits that, if bypassed, make it easier for spam transactions to propagate. These were formally acknowledged as vulnerabilities in the CVE database. From my vantage point, the real issue isn’t just the bugs themselves — it’s the signal that Core has become slower to prioritize spam resistance fixes, while alternative implementations like Knots move faster on them. This dynamic is worth watching. Do you see this as a healthy sign of client diversity, or as a growing problem for Bitcoin’s base layer hygiene?

    Post summary

    The post highlights two Bitcoin Core CVEs that remain unpatched in Core but have been fixed in Knots 25.1, underscoring concerns about Bitcoin’s patching pace and the rise of alternative implementations.

    0000079
    39.8K followersView on X
  • Ziopat@PatriceinMilano
    Patch

    Luke de Wolf highlighted two CVEs in Bitcoin Core (CVE-2023-50428 and CVE-2024-34149) that were never fixed in Core but were addressed in Knots 25.1. Both relate to policy limits that, if bypassed, make it easier for spam transactions to propagate. These were formally acknowledged as vulnerabilities in the CVE database. From my vantage point, the real issue isn’t just the bugs themselves — it’s the signal that Core has become slower to prioritize spam resistance fixes, while alternative implementations like Knots move faster on them. This dynamic is worth watching. Do you see this as a healthy sign of client diversity, or as a growing problem for Bitcoin’s base layer hygiene?

    Post summary

    Two Bitcoin Core CVEs were never patched in Core but were fixed in Knots 25.1; the post highlights policy‑limit related spam vulnerabilities without reporting active exploitation or a PoC.

    0000064
    39.8K followersView on X
  • Axexang@axexang
    Patch

    @scottmsul @matteopelleg Bip 110 will make Bitcoin sound money again by fixing the major security issues that "core" refused deliberately to fix (CVE-2023-50428 and CVE-2024-34149).

    Post summary

    The tweet announces that Bip 110 will deliver fixes for CVE-2023-50428 and CVE-2024-34149, underscoring an upcoming patch for these vulnerabilities.

    00000114
    1.2K followersView on X
  • Axexang@axexang
    General

    @gsovereigntyg @orthodoxbitcoin Of course not; This new "core" team has only one objective letting the major security issues opened: CVE-2023-50428 and CVE-2024-34149 which is required if you want to transform Bitcoin into a regular sh|tcoin. As you could see their major achievement is from 2023 and it shows.

    Post summary

    The tweet merely cites two CVE identifiers with no additional information on exploitation, patching, or technical details, making it a general mention.

    0000071
    1.2K followersView on X

Explore more