Besu 26.9.0: security release for Ethereum node operators
Besu 26.9.0 (released 2026-09-28) includes security fixes according to its release notes. Ethereum node operators running Besu should review and upgrade.
Vuln-watch · relayed from an upstream security release; see Source & attribution below
Summary
Besu 26.9.0 (released 2026-09-28) includes security fixes according to its release notes. Ethereum node operators running Besu should review and upgrade.
Affected
- Besu (hyperledger/besu) versions before 26.9.0
From the release notes
Amsterdam scheduled on Sepolia — Tue 6 Oct 2026, 13:53:36 UTC (timestamp 1791294816). Sepolia operators must upgrade before then. This release contains security fixes. Operators are advised to upgrade promptly. Details will be published in security advisories on https://github.com/besu-eth/besu/security/advisories after operators have had an opportunity to upgrade. ## Breaking Changes - BlockSimulationParameter.Builder.enforceConsensusGasLimitCaps() is renamed to enforceConsensusGasLimit(). The flag now also controls whether the EIP-1559 gas limit adjustment algorithm is applied: when true (plugin/block-production path) getNextGasLimit() is used; when false (default, eth_simulateV1 path) the parent gas limit is inherited unchanged, matching geth and Nethermind. #11254 - BlockResult constructor signatures no longer accept a totalDifficulty parameter. The field was already ignored (
Recommended actions
- Upgrade Besu to 26.9.0 or later
- Check the release notes for any coordinated upgrade deadline or required configuration change
Source & attribution
This 0xCERT advisory relays the Besu 26.9.0 release notes: https://github.com/besu-eth/besu/releases/tag/26.9.0. Refer to the upstream project for the authoritative record and any follow-up security advisories.
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-09-28 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0183/signed.txt | gpg --verify