Description
Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14.
Published: 2026-05-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Bitcoin Core before version 28.x includes an undisclosed flaw that first appears in release 0.14. The nature of the vulnerability is not described by the vendor, and thus the exact capabilities of an attacker cannot be determined from public information. It may allow for unauthorized data disclosure, manipulation of transaction data, or denial of service against the node. Because the weakness type is unspecified, it is prudent to treat it as a high-impact flaw that could affect the confidentiality, integrity, or availability of a Bitcoin node.

Affected Systems

The issue affects all Bitcoin Core nodes running any 0.14 version through the latest 28.x releases. The Bitcoin Core project is the vendor, and there are no more granular product names. Users operating a full node or lightweight client that relies on the Core back‑end should consider their installation vulnerable until a patch is released.

Risk and Exploitability

Without a disclosed exploit or CVSS score, the exact risk level is indeterminate. The Probability of exploitation (EPSS) is not available, so no quantitative likelihood can be assigned. Nevertheless, Bitcoin Core is widely deployed worldwide, making it an attractive target. If this flaw can be triggered via a network message, a remote attacker could potentially compromise a node even without local access. The lack of KEV listing indicates no known public exploits yet, but the absence of evidence should not imply absence of risk. Organizations should treat this as a potential remote vulnerability and prepare mitigation steps until a fix is released.

Generated by OpenCVE AI on May 5, 2026 at 21:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched Bitcoin Core release as soon as one is available
  • Restrict peer connections with a firewall or network policy to limit exposure to untrusted nodes
  • Monitor node logs and network traffic for anomalous activity indicative of exploitation

Generated by OpenCVE AI on May 5, 2026 at 21:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 05 May 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Bitcoincore
Bitcoincore bitcoin Core
Vendors & Products Bitcoincore
Bitcoincore bitcoin Core

Tue, 05 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Undisclosed Security Issue in Bitcoin Core Affecting Versions 0.14 and Up
Weaknesses CWE-200

Tue, 05 May 2026 20:00:00 +0000

Type Values Removed Values Added
Description Bitcoin Core through 28.x has a security issue, the details of which are not disclosed. The earliest affected version is 0.14.
References

Subscriptions

Bitcoincore Bitcoin Core
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-05T19:35:15.000Z

Reserved: 2024-11-18T00:00:00.000Z

Link: CVE-2024-52911

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-05T20:16:34.923

Modified: 2026-05-05T20:16:34.923

Link: CVE-2024-52911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-05T22:00:11Z

Weaknesses