Bcoin is a lightweight, focused Bitcoin library and node implementation where the vulnerability profile centers on resource-consumption and cryptographic-handling issues. The recurring weakness classes—uncontrolled resource consumption and use of broken or risky cryptographic algorithms—reflect the demands of peer-to-peer network protocols and cryptographic operations inherent to blockchain implementations; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bcoin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50475CRITICAL An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocke | Dec 21, 2023 | 9.1 | 28 | NO | NO |
CVE-2018-17145HIGH Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INV | Sep 10, 2020 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bcoin.
Media articles that mention a CVE ID that affects a product developed by Bcoin — matched by CVE ID, not by vendor name.