High severity7.5NVD Advisory· Published Mar 16, 2020· Updated Jun 17, 2026
CVE-2017-12842
CVE-2017-12842
Description
Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur. Completing the attack would cost more than a million dollars, and is relevant mainly only in situations where an autonomous system relies solely on an SPV proof for transactions of a greater dollar amount.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*range: <0.14.0
- (no CPE)range: <0.14
- Bitcoin/Coredescription
Patches
Vulnerability mechanics
References
3- bitslog.wordpress.com/2018/06/09/leaf-node-weakness-in-bitcoin-merkle-tree-design/nvdThird Party Advisory
- en.bitcoin.it/wiki/Common_Vulnerabilities_and_ExposuresnvdVendor Advisory
- lists.linuxfoundation.org/pipermail/bitcoin-dev/2019-February/016697.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.