CVE-2012-1909: Bitcoin Core

Medium severity, CVSS 5.0. EPSS: 2.9% chance of exploitation in the next 30 days.

The Bitcoin protocol, as used in bitcoind before 0.4.4, wxBitcoin, Bitcoin-Qt, and other programs, does not properly handle multiple transactions with the same identifier, which allows remote attackers to cause a denial of service (unspendable transaction) by leveraging the ability to create a duplicate coinbase transaction.

Affected products

  • Bitcoin Bitcoin Core: any version; up to and including 0.4.4; version 0.3.4 only; version 0.3.5 only; version 0.3.8 only; version 0.3.10 only; …
  • Bitcoin Wxbitcoin: any version

Published 2012-08-06. Last modified 2026-06-16.