Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
High0xCERT-2026-0183·

Besu 26.9.0: security release for Ethereum node operators

Besu 26.9.0 (released 2026-09-28) includes security fixes according to its release notes. Ethereum node operators running Besu should review and upgrade.

Vuln-watch · relayed from an upstream security release; see Source & attribution below

Affected chainsEthereum

Summary

Besu 26.9.0 (released 2026-09-28) includes security fixes according to its release notes. Ethereum node operators running Besu should review and upgrade.

Affected

  • Besu (hyperledger/besu) versions before 26.9.0

From the release notes

Amsterdam scheduled on Sepolia — Tue 6 Oct 2026, 13:53:36 UTC (timestamp 1791294816). Sepolia operators must upgrade before then. This release contains security fixes. Operators are advised to upgrade promptly. Details will be published in security advisories on https://github.com/besu-eth/besu/security/advisories after operators have had an opportunity to upgrade. ## Breaking Changes - BlockSimulationParameter.Builder.enforceConsensusGasLimitCaps() is renamed to enforceConsensusGasLimit(). The flag now also controls whether the EIP-1559 gas limit adjustment algorithm is applied: when true (plugin/block-production path) getNextGasLimit() is used; when false (default, eth_simulateV1 path) the parent gas limit is inherited unchanged, matching geth and Nethermind. #11254 - BlockResult constructor signatures no longer accept a totalDifficulty parameter. The field was already ignored (

Recommended actions

  • Upgrade Besu to 26.9.0 or later
  • Check the release notes for any coordinated upgrade deadline or required configuration change

Source & attribution

This 0xCERT advisory relays the Besu 26.9.0 release notes: https://github.com/besu-eth/besu/releases/tag/26.9.0. Refer to the upstream project for the authoritative record and any follow-up security advisories.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-09-28 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0183/signed.txt | gpg --verify