Besu released version 26.7.1 to repair 5 security leaks discovered by CertiK Hole
Besu, the client of the Taifeng, released version 26.7.1 on 27 July, repairing five security loopholes discovered by CertiK and issued four security announcements on 14 August. According to Jialiang Chang, Director of Security Engineering and Senior Audit Partner of CertiK, the patch-up arrangement provides an 18-day buffer period during which nodal operators can identify affected deployments, test new versions and complete upgrades. The loopholes relate to block broadcast processing, the cache of future highly agreed proposals, websocket subscription restrictions and the creation of json-rpc filters. CertiK conducts confrontational testing in a private testing network through the chain scan method and provides the Besu team with replicable testing tools. CertiK is updating chain scan to run a round-the-clock multinodes test。
