CVE-2017-18350: Bitcoin Core

Medium severity, CVSS 5.9. EPSS: 1.3% chance of exploitation in the next 30 days.

bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.

Affected products

  • Bitcoin Bitcoin Core: before 0.15.1 (fixed in 0.15.1)

Published 2020-03-12. Last modified 2026-06-17.