Bitcoin Core and its related client implementations form a narrowly scoped but prominent software portfolio at the foundation of the Bitcoin network, where vulnerabilities can affect the security and availability of both individual nodes and network infrastructure. The recurring exposure centers on resource-management and information-disclosure weaknesses—including uncontrolled resource consumption, allocation without limits or throttling, integer overflow, and sensitive-information exposure—that arise from the protocol-parsing and peer-communication demands of distributed-network software. These weakness classes reflect the tension between accepting untrusted network messages and protecting node availability and data confidentiality, and they span the full lifecycle of the Bitcoin reference implementation. Defenders running Bitcoin infrastructure should prioritize timely patching of the reference client and monitor for network-wide implications of disclosed vulnerabilities; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bitcoin over time
Signals from CVEs in this vendor scope (57 CVEs).
57 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17144HIGH Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (applicatio | Sep 19, 2018 | 7.5 | 35 | NO | NO |
CVE-2021-3401CRITICAL Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt progra | Feb 4, 2021 | 9.8 | 34 | NO | NO |
CVE-2010-5139HIGH Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bitcoins via a crafted Bitcoin transaction | Aug 6, 2012 | 7.5 | 32 | NO | NO |
CVE-2017-12842HIGH Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur. C | Mar 16, 2020 | 7.5 | 27 | NO | NO |
CVE-2013-3220MEDIUM bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8rc2, 0.6.x before 0.6.5rc2, and 0.7.x before 0.7.3rc2, and wxBitcoin, do not properly consider whether a block's size cou | Aug 2, 2013 | 6.4 | 27 | NO | NO |
CVE-2018-17145HIGH Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INV | Sep 10, 2020 | 7.5 | 26 | NO | NO |
CVE-2017-9230HIGH The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with a variety of initial 64-byte chunks followed by the same 16 | May 24, 2017 | 7.5 | 26 | NO | NO |
CVE-2013-2292HIGH bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity consumption) by mining a block to create a nonstandard Bitcoin transactio | Mar 12, 2013 | 7.8 | 26 | NO | NO |
CVE-2025-46597HIGH Bitcoin Core 0.13.0 through 29.x has an integer overflow. | Mar 20, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-35202HIGH Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message th | Oct 10, 2024 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (57 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bitcoin.
Media articles that mention a CVE ID that affects a product developed by Bitcoin — matched by CVE ID, not by vendor name.