validator-node

1 article
Sort: New Top Best
clear filter
0 6/10
Sui
vulnerability

A high-severity DoS vulnerability in Sui's Narwhal consensus layer allowed attackers to crash validator nodes via Out-of-Memory (OOM) attacks by sending a single malicious request with 1.2M certificate digests (37MB payload), bypassing the absence of response limits and timeout handling in the get_certificates() function. The vulnerability was patched by removing the vulnerable GetCertificates and GetPayloadAvailability handlers, with the researcher earning a $50,000 SUI bounty.

Sui Immunefi @F4lt Narwhal Bullshark Move MystenLabs
immunefi.com · unknown · 4 hours ago · details