CVE-2023-34451 is a high-severity vulnerability affecting CometBFT versions v0.37.0, v0.37.1, v0.34.28, and all previous releases of the CometBFT repo2. It stems from a synchronization issue between the mempool's transaction list and map, allowing duplicate transactions to become permanently stuck. This can be exploited remotely with low attack complexity (CVSS 8.2, High) to conduct denial-of-service attacks by overwhelming a node's mempool, requiring a restart to clear. There is no evidence of active exploitation, public exploit code, or significant community discussion, but a patch is available in versions v0.34.29 and v0.37.2, and workarounds like increasing cache_size or restricting RPC access can mitigate risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.34.28, < 0.34.29CPE matchmatch criteria | cpe:2.3:a:cometbft:cometbft:*:*:*:*:*:*:*:* | ||
>= 0.37.0, < 0.37.2CPE matchmatch criteria | cpe:2.3:a:cometbft:cometbft:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.