CometBFT is a Byzantine fault-tolerant consensus engine used in blockchain and distributed ledger systems, with its vulnerability exposure centered on the core CometBFT product itself. The observed weaknesses cluster around resource management issues—specifically memory-release defects and unbounded resource allocation—reflecting the demands of a consensus protocol implementation that must handle byzantine or malicious peers without denial-of-service compromise. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cometbft over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34451HIGH CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many machines. The mempool maintains two data structures to keep | Jul 3, 2023 | 8.2 | 24 | NO | NO |
CVE-2023-34450MEDIUM CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many machines. An internal modification made in versions 0.34.28 | Jul 3, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cometbft.
Media articles that mention a CVE ID that affects a product developed by Cometbft — matched by CVE ID, not by vendor name.