CVE-2023-33297: Bitcoin Core

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.

Affected products

  • Bitcoin Bitcoin Core: before 24.1 (fixed in 24.1)

Published 2023-05-22. Last modified 2026-06-17.