CVE-2018-17144: Bitcoin Core

High severity, CVSS 7.5. EPSS: 6.7% chance of exploitation in the next 30 days.

Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.

Affected products

  • Bitcoin Bitcoin Core: from 0.14.0, before 0.14.3 (fixed in 0.14.3); from 0.15.0, before 0.15.2 (fixed in 0.15.2); from 0.16.0, before 0.16.3 (fixed in 0.16.3)
  • Bitcoinknots Bitcoin Knots: from 0.14.0, before 0.16.3 (fixed in 0.16.3)

Published 2018-09-19. Last modified 2026-06-17.