CVE-2024-55563

Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timelock Contract) can be changed because a flood of transaction traffic prevents propagation of certain Lightning channel transactions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*

History

22 May 2025, 16:56

Type Values Removed Values Added
CPE cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*
First Time Bitcoin
Bitcoin bitcoin Core
References () https://ariard.github.io - () https://ariard.github.io - Third Party Advisory
References () https://bitcoincore.org - () https://bitcoincore.org - Product
References () https://delvingbitcoin.org/t/full-disclosure-transaction-relay-throughput-overflow-attacks-against-off-chain-protocols/1305 - () https://delvingbitcoin.org/t/full-disclosure-transaction-relay-throughput-overflow-attacks-against-off-chain-protocols/1305 - Issue Tracking
References () https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures - () https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures - Third Party Advisory
References () https://gnusha.org/pi/bitcoindev/CALZpt+EptER=p+P7VN3QAb9n=dODA9_LnR9xZwWpRsdAwedv=w@mail.gmail.com/T/#u - () https://gnusha.org/pi/bitcoindev/CALZpt+EptER=p+P7VN3QAb9n=dODA9_LnR9xZwWpRsdAwedv=w@mail.gmail.com/T/#u - Mailing List

04 Mar 2025, 22:15

Type Values Removed Values Added
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

09 Dec 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 01:15

Updated : 2025-05-22 16:56


NVD link : CVE-2024-55563

Mitre link : CVE-2024-55563

CVE.ORG link : CVE-2024-55563


JSON object : View

Products Affected

bitcoin

  • bitcoin_core
CWE
CWE-770

Allocation of Resources Without Limits or Throttling