CVE-2023-34450 is a deadlock vulnerability in CometBFT versions 0.34.28 and 0.37.1, caused by an internal modification to JSON serialization of the PeerState struct. This medium severity vulnerability (CVSS 5.3) can lead to a denial of service, potentially halting a node or an entire two-node network, depending on how it's triggered. While there are no known active exploits, exploit code, or significant community discussion, workarounds and patches (versions 0.34.29 and 0.37.2) are available to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.34.28, < 0.34.29CPE matchmatch criteria | cpe:2.3:a:cometbft:cometbft:*:*:*:*:*:*:*:* | ||
>= 0.37.1, < 0.37.2CPE matchmatch criteria | cpe:2.3:a:cometbft:cometbft:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.