
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54604 is an Uncontrolled Resource Consumption vulnerability (issue 1 of 2) in Bitcoin Core through version 29.0, allowing network-based denial-of-service attacks via excessive system resource exhaustion. The vulnerability was publicly disclosed on October 24, 2025, via the Bitcoin Core security advisory, and was registered in NVD on October 28, 2025. It affects all Bitcoin Core releases up to and including 29.0, with the fix introduced in version 30.0. It carries a CVSS v3.1 base score of 7.5 (High) (Bitcoin Core Advisory, Red Hat CVE).
The vulnerability is classified under CWE-400 (Uncontrolled Resource Consumption), meaning Bitcoin Core fails to properly limit the consumption of system resources when processing certain network-based inputs. An unauthenticated remote attacker can send specially crafted network requests that cause the node to consume excessive CPU, memory, or other system resources without adequate throttling or bounds checking. No authentication or user interaction is required, and the attack vector is entirely network-based. The Bitcoin Core project notes this is the first of two related resource consumption issues disclosed simultaneously (see also CVE-2025-54605) (Bitcoin Core Advisory).
Successful exploitation results in a Denial of Service (DoS) condition, with high availability impact — the Bitcoin Core node can become unresponsive or crash entirely, disrupting participation in the Bitcoin peer-to-peer network. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Operators running Bitcoin Core nodes for wallet services, exchanges, or infrastructure relying on continuous node availability are most at risk, as a crashed or unresponsive node could halt transaction broadcasting and block validation (Bitcoin Core Advisory, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Bitcoin Core Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported. The vulnerability is described as low severity by the Bitcoin Core project, consistent with its classification as a DoS-only issue requiring no authentication.
The primary remediation is to upgrade Bitcoin Core to version 30.0 or later, which contains the fix for this vulnerability (Bitcoin Core Advisory, GitHub Releases). As interim mitigations, operators should implement network-level controls to restrict unnecessary inbound connections to the Bitcoin Core P2P port (default: 8333), use firewalls to limit exposure to untrusted peers, and monitor system resource utilization for anomalous spikes. No configuration-only workaround has been officially documented by the Bitcoin Core project.
The Bitcoin Core project disclosed this vulnerability alongside three others (CVE-2025-54605, CVE-2025-46597, CVE-2025-46598) as part of a coordinated batch disclosure on October 24, 2025, characterizing all four as low severity. Community discussion on Bitcoin Stack Exchange raised questions about whether fixes would be backported to the 28.x or 29.x release branches (Bitcoin Stack Exchange). Crypto news outlets covered the disclosure with measured tone, noting the fixes were bundled into the v30.0 release (Bitcoin Ethereum News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."