Medium severity5.3NVD Advisory· Published Dec 9, 2023· Updated Jun 17, 2026
CVE-2023-50428
CVE-2023-50428
Description
In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023. NOTE: although this is a vulnerability from the perspective of the Bitcoin Knots project, some others consider it "not a bug."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*range: >=0.9,<=26.0
- (no CPE)
- (no CPE)range: <=26.0
- Range: <25.1.knots20231115
Patches
Vulnerability mechanics
References
6- en.bitcoin.it/wiki/Common_Vulnerabilities_and_ExposuresnvdThird Party Advisory
- twitter.com/LukeDashjr/status/1732204937466032285nvdIssue TrackingThird Party Advisory
- github.com/bitcoin/bitcoin/pull/28408nvdIssue Tracking
- github.com/bitcoin/bitcoin/tagsnvdProduct
- github.com/bitcoinknots/bitcoin/blob/aed49ce8989334c364a219a6eb016a3897d4e3d7/doc/release-notes.mdnvdRelease Notes
- github.com/bitcoin/bitcoin/blob/65c05db660b2ca1d0076b0d8573a6760b3228068/src/kernel/mempool_options.hnvd
News mentions
0No linked articles in our index yet.