CVE-2025-29072: Nethermind Juno

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations.

Affected products

Published 2025-03-27. Last modified 2026-06-17.