CVE-2025-46598
Bitcoin Core vulnerability analysis and mitigation

Overview

CVE-2025-46598 is a denial-of-service vulnerability in Bitcoin Core through version 29.0 that can be triggered by a specially crafted transaction. The flaw is classified as asymmetric resource consumption (CWE-405), allowing an unauthenticated network attacker to cause disproportionate resource usage on a target node. It was publicly disclosed on October 24, 2025 via the Bitcoin Core security advisory page, with CVE publication on March 20, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Bitcoin Core Advisory).

Technical details

The root cause is asymmetric resource consumption (CWE-405), where a crafted transaction causes a Bitcoin Core node to expend significantly more processing or memory resources than the attacker expends to send it. This amplification effect allows a low-effort network-level attack to degrade or disrupt node availability. No authentication or special privileges are required; the attacker only needs network access to submit transactions to the target node. The fix was introduced in Bitcoin Core 30.0, with the vulnerability affecting all versions prior to 30.0 (Bitcoin Core Advisory, Red Hat Advisory).

Impact

Successful exploitation results in denial of service against the affected Bitcoin Core node, causing node unavailability and service disruption. There is no impact on confidentiality or integrity — only availability is affected. In a broader network context, widespread exploitation targeting multiple nodes could contribute to instability in the Bitcoin peer-to-peer network, though the limited CVSS availability impact score (Low) suggests the effect is constrained in scope (Red Hat Advisory, Bitcoin Core Advisory).

Exploitability

There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported. The EPSS score is extremely low at approximately 0.006%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been made (Red Hat Advisory, Bitcoin Core Advisory).

Mitigation and workarounds

The primary remediation is upgrading Bitcoin Core to version 30.0 or later, which contains the fix for this vulnerability. All versions through 29.0 are affected; operators running Bitcoin Core 29.x or earlier should prioritize upgrading to 30.0 or a subsequent release (30.1, 30.2, 31.0, etc.) (Bitcoin Core Releases, Bitcoin Core Advisory). As an interim measure until patching is possible, administrators should consider implementing network-level controls to restrict which peers can submit transactions to the node, and monitor for unusual transaction patterns that could indicate exploitation attempts.

Community reactions

Bitcoin Core disclosed this vulnerability alongside three other low-severity issues (CVE-2025-54604, CVE-2025-54605, CVE-2025-46597) as part of a coordinated disclosure with the v30.0 release, which generated moderate community discussion. Coverage appeared on Bitcoin-focused outlets such as Bitcoin Ethereum News and U.Today, characterizing the four issues as low-severity. The Bitcoin Stack Exchange community raised questions about whether backports to the 29.x or 28.x release series would be provided. Bitcoin Optech also discussed the disclosures in their February 2026 podcast (Bitcoin Ethereum News, Bitcoin Optech Podcast, Stack Exchange).

Additional resources


SourceThis report was generated using AI

Related Bitcoin Core vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-46597HIGH7.5
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesMar 20, 2026
CVE-2025-54605HIGH7.5
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2025-54604HIGH7.5
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2025-46598MEDIUM5.3
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesMar 20, 2026
CVE-2024-55563MEDIUM5.3
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoNoDec 09, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management