CVE-2019-25220: Bitcoin Core

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work before committing to store it.

Affected products

  • Bitcoin Bitcoin Core: before 24.0.1 (fixed in 24.0.1)

Published 2024-11-18. Last modified 2026-06-17.