▁▂▃▅▇█▇▅▃▂▁▁▂▃▅▇█▇▅▃▂▁▁▂▃▅▇█▇▅▃▂▁▁▂▃▅▇█▇▅▃▂▁▁▂▃▅▇█▇▅▃▂▁
B A R R E T E N B E R G · 5 · 2 · 1
Date: 2026-10-07 · Tag: v5.2.1 · Baseline: v5.2.0 · Patch release with security fix for barretenberg users only; no action needed for the Aztec network
bb.js: @aztec/bb.js@5.2.1
Summary
v5.2.1 is a single-fix security patch for barretenberg (bb / bb.js). The native UltraHonk verifier now rejects proofs whose recursive pairing accumulator is malformed.
This release does not affect the Aztec network. Circuits, verification keys, protocol constants and contracts are identical to v5.2.0. v5.2.0 and v5.2.1 nodes interoperate, and node operators, contract developers and wallet/PXE users do not need to upgrade.
Who should upgrade
- Recommended for Noir developers using barretenberg and other direct barretenberg users who verify UltraHonk proofs natively, through the
bbCLI,@aztec/bb.jsorbarretenberg-rs, especially for circuits that recursively verify other proofs. - Not needed for the Aztec network. Node operators, sequencers, provers, contract developers and wallet/PXE users can stay on v5.2.0.
Security fix
- Native UltraHonk verifier now rejects malformed recursive pairing accumulators. A proof that recursively verifies other proofs carries a pairing-point accumulator (P0, P1) in its public inputs. When exactly one of P0 or P1 was the point at infinity, recent versions of the native verifier accepted the proof (GHSA-2hc8-mq24-76v2, high). Older versions threw an exception, or aborted the WASM instance in bb.js, so a crafted proof could crash a service that verifies untrusted proofs (GHSA-73xc-j27q-wg75, medium). The verifier now returns a verification failure in both cases. Only the native verifier changes; in-circuit recursive verifiers and the Solidity verifier are untouched, so no verification keys change (#25616).
What changed since v5.2.0
- #25616 — fix(bb): reject mixed-infinity recursive accumulators