CVE-2025-29072: Nethermind Juno
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the "cairo-lang-starknet-classes" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations.
Affected products
- Nethermind Juno: before 0.12.5 (fixed in 0.12.5)
Published 2025-03-27. Last modified 2026-06-17.