CVE-2024-52918: Bitcoin Core

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter for a URL that has a large file.

Affected products

  • Bitcoin Bitcoin Core: before 0.20.0 (fixed in 0.20.0)

Published 2024-11-18. Last modified 2026-06-17.