CVE-2024-35202General(bitcoin / bitcoin_core)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called twice for one PartiallyDownloadedBlock instance.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bitcoin_core

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-28); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
bitcoin_core

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-02-28: 2Mentions · 2026-03-11: 2Technical Details · 2026-03-11: 202-2803-11
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-282
General2
2026-03-112
Disclosure2
Full discourse4 posts
  • Mike Schmidt@bitschmidty
    Disclosure

    Niklas finds bugs across Bitcoin and Lightning implementations. He added a bunch of testing in Bitcoin Core to find bugs. He created and open sourced his own fuzz testing framework so he could find even more bugs, faster. He found and fixed CVE-2024-35202 a high severity bug that allowed arbitrary crashing of Bitcoin Core nodes. And much more. Thank you, @dergoegge, and heres to four years 🍻

    Post summary

    Niklas discovered and patched CVE-2024-35202, a high‑severity bug causing arbitrary crashes in Bitcoin Core nodes, and has developed a fuzz framework to find further vulnerabilities.

    3200137815.5K
    4.8K followersView on X
  • Brink@bitcoinbrink
    Disclosure

    "His own disclosed findings include CVE-2024-35202, a bug in Bitcoin Core that allowed an attacker to crash nodes on the Bitcoin network essentially at will. Had an attacker discovered this bug, the potential damage and consequences to Bitcoin could have been severe."

    Post summary

    The post announces a newly disclosed CVE‑2024‑35202 affecting Bitcoin Core, noting it can cause node crashes, but no PoC, exploit, or patch is mentioned.

    10040288
    13.3K followersView on X
  • Grok@grok
    General

    It's balanced—not a puff piece. Praises Core's maturing fuzzing (200+ tests finding bugs like CVE-2024-35202), formalized disclosure policy (post-2024, with severity tiers & delayed releases), and testing layers. But calls historical "no bugs" narrative "dangerous & inaccurate," notes tradeoffs like "paternalistic" power in the security team, and quotes critics on concentrated dev knowledge. Solid read on real processes.

    Post summary

    The text praises fuzzing successes and policy changes, mentions CVE‑2024‑35202, but offers no technical, exploit, or patch details.

    1000077
    8.3M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-35202 2 - CVE-2019-12735 3 - CVE-2025-40552 4 - CVE-2026-21253 5 - CVE-2026-28515 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs but provides no additional technical or operational information.

    00000342
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbitcoinbitcoin_core---

Explore more