CVE-2025-54604
Bitcoin Core vulnerability analysis and mitigation

Overview

CVE-2025-54604 is an Uncontrolled Resource Consumption vulnerability (issue 1 of 2) in Bitcoin Core through version 29.0, allowing network-based denial-of-service attacks via excessive system resource exhaustion. The vulnerability was publicly disclosed on October 24, 2025, via the Bitcoin Core security advisory, and was registered in NVD on October 28, 2025. It affects all Bitcoin Core releases up to and including 29.0, with the fix introduced in version 30.0. It carries a CVSS v3.1 base score of 7.5 (High) (Bitcoin Core Advisory, Red Hat CVE).

Technical details

The vulnerability is classified under CWE-400 (Uncontrolled Resource Consumption), meaning Bitcoin Core fails to properly limit the consumption of system resources when processing certain network-based inputs. An unauthenticated remote attacker can send specially crafted network requests that cause the node to consume excessive CPU, memory, or other system resources without adequate throttling or bounds checking. No authentication or user interaction is required, and the attack vector is entirely network-based. The Bitcoin Core project notes this is the first of two related resource consumption issues disclosed simultaneously (see also CVE-2025-54605) (Bitcoin Core Advisory).

Impact

Successful exploitation results in a Denial of Service (DoS) condition, with high availability impact — the Bitcoin Core node can become unresponsive or crash entirely, disrupting participation in the Bitcoin peer-to-peer network. There is no confidentiality or integrity impact; the vulnerability is limited to availability. Operators running Bitcoin Core nodes for wallet services, exchanges, or infrastructure relying on continuous node availability are most at risk, as a crashed or unresponsive node could halt transaction broadcasting and block validation (Bitcoin Core Advisory, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Bitcoin Core Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported. The vulnerability is described as low severity by the Bitcoin Core project, consistent with its classification as a DoS-only issue requiring no authentication.

Mitigation and workarounds

The primary remediation is to upgrade Bitcoin Core to version 30.0 or later, which contains the fix for this vulnerability (Bitcoin Core Advisory, GitHub Releases). As interim mitigations, operators should implement network-level controls to restrict unnecessary inbound connections to the Bitcoin Core P2P port (default: 8333), use firewalls to limit exposure to untrusted peers, and monitor system resource utilization for anomalous spikes. No configuration-only workaround has been officially documented by the Bitcoin Core project.

Community reactions

The Bitcoin Core project disclosed this vulnerability alongside three others (CVE-2025-54605, CVE-2025-46597, CVE-2025-46598) as part of a coordinated batch disclosure on October 24, 2025, characterizing all four as low severity. Community discussion on Bitcoin Stack Exchange raised questions about whether fixes would be backported to the 28.x or 29.x release branches (Bitcoin Stack Exchange). Crypto news outlets covered the disclosure with measured tone, noting the fixes were bundled into the v30.0 release (Bitcoin Ethereum News).

Additional resources


SourceThis report was generated using AI

Related Bitcoin Core vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-46597HIGH7.5
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesMar 20, 2026
CVE-2025-54605HIGH7.5
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2025-54604HIGH7.5
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2025-46598MEDIUM5.3
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesMar 20, 2026
CVE-2024-55563MEDIUM5.3
  • Bitcoin Core logoBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoNoDec 09, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management