Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

berachain/beacon-kit
main @ b15b0a9
43
Fixes
0
CVEs
HIGH
Peak severity
45.7%
Coverage
Highlights
Denial of Service: 20 prior fixes. Scrutinize any change in this area.
beacon/blockchain: most-fixed (4 issues). Treat as high-risk during review.
25 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Denial of Service: Publicly exposed Merkle proof and filtering APIs did not validate slice lengths or user-supplied validator indices, leading to panic-induced Denial of Service. Future APIs must strictly enforce input limits and map lookups instead of linear slice searches.
Auth Bypass: The BeaconDepositContract lacks authorization controls on deposits and withdrawals, allowing arbitrary callers to simulate or trigger unauthorized withdrawals and emissions. Upgrades must ensure rigorous validation of the msg.sender during state changes.
Verification Bypass: KZG inclusion proofs for blobs were validated against a caller-provided root rather than the inner block header's body root, allowing verification bypasses. Ensuring correct root resolution is fundamental to block and sidecar verification.