Headline:
CVE-2025-54604 - Disk filling from spoofed self connections

Summary:
This lead was identified from Bitcoin Core Blog. It has been saved for accountability coverage and should be reviewed against the original source before expansion.

What the record says:
The source headline is: CVE-2025-54604 - Disk filling from spoofed self connections. The source summary says: Disclosure of the details of a log-filling bug which allowed an attacker to fill up the disk space of a victim node by faking self-connections. Exploitability of this bug is limited, and it would take a long time before it would cause the victim to run out of disk space. A fix was released on October 10th 2025 in Bitcoin Core v30.0. This issue is considered Low severity. Details Bitcoin Core would unconditionally log in case of self-connection. This could be exploited by an attacker by waiting for a victim to connect to it and reusing the version message nonce to establish many connections to the victim, causing it to detect those attempts as self-connections. However, exploitability is limited because the initial connection from the victim will timeout after 60 seconds by default. This issue was fixed by implementing log rate-limiting across the board, also preventing future issues of t

Why it matters:
This may be relevant to public accountability, consumer protection, government oversight, fraud monitoring, or financial transparency depending on the source record.

What is not yet proven:
This draft should not be treated as proof beyond what the linked source directly supports. Avoid adding accusations, private information, or copied text from the original source.

Source:
https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-54604/

AI writer note: OPENAI_API_KEY is empty, so this was generated with the built-in safe fallback writer.