
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46598 is a denial-of-service vulnerability in Bitcoin Core through version 29.0 that can be triggered by a specially crafted transaction. The flaw is classified as asymmetric resource consumption (CWE-405), allowing an unauthenticated network attacker to cause disproportionate resource usage on a target node. It was publicly disclosed on October 24, 2025 via the Bitcoin Core security advisory page, with CVE publication on March 20, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Bitcoin Core Advisory).
The root cause is asymmetric resource consumption (CWE-405), where a crafted transaction causes a Bitcoin Core node to expend significantly more processing or memory resources than the attacker expends to send it. This amplification effect allows a low-effort network-level attack to degrade or disrupt node availability. No authentication or special privileges are required; the attacker only needs network access to submit transactions to the target node. The fix was introduced in Bitcoin Core 30.0, with the vulnerability affecting all versions prior to 30.0 (Bitcoin Core Advisory, Red Hat Advisory).
Successful exploitation results in denial of service against the affected Bitcoin Core node, causing node unavailability and service disruption. There is no impact on confidentiality or integrity — only availability is affected. In a broader network context, widespread exploitation targeting multiple nodes could contribute to instability in the Bitcoin peer-to-peer network, though the limited CVSS availability impact score (Low) suggests the effect is constrained in scope (Red Hat Advisory, Bitcoin Core Advisory).
There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported. The EPSS score is extremely low at approximately 0.006%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been made (Red Hat Advisory, Bitcoin Core Advisory).
The primary remediation is upgrading Bitcoin Core to version 30.0 or later, which contains the fix for this vulnerability. All versions through 29.0 are affected; operators running Bitcoin Core 29.x or earlier should prioritize upgrading to 30.0 or a subsequent release (30.1, 30.2, 31.0, etc.) (Bitcoin Core Releases, Bitcoin Core Advisory). As an interim measure until patching is possible, administrators should consider implementing network-level controls to restrict which peers can submit transactions to the node, and monitor for unusual transaction patterns that could indicate exploitation attempts.
Bitcoin Core disclosed this vulnerability alongside three other low-severity issues (CVE-2025-54604, CVE-2025-54605, CVE-2025-46597) as part of a coordinated disclosure with the v30.0 release, which generated moderate community discussion. Coverage appeared on Bitcoin-focused outlets such as Bitcoin Ethereum News and U.Today, characterizing the four issues as low-severity. The Bitcoin Stack Exchange community raised questions about whether backports to the 29.x or 28.x release series would be provided. Bitcoin Optech also discussed the disclosures in their February 2026 podcast (Bitcoin Ethereum News, Bitcoin Optech Podcast, Stack Exchange).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."