Nimiq是Nimiq开源的一个Albatross协议的Rust实现。 Nimiq 1.3.0之前版本存在安全漏洞,该漏洞源于nimiq-transaction中HistoryTreeProof::verify在格式错误的证明上触发panic,其中history.len() != positions.len()。证明对象源自不受信任的p2p响应,因此在网络边界上受攻击者控制,直到被验证。恶意对等方可以通过返回长度不匹配的特制包含证明来触发崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nimiq | nimiq-transaction | < 1.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33471 | 9.6 CRITICAL | nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation |
| CVE-2026-34063 | 7.5 HIGH | network-libp2p: Peer can crash the node by opening discovery protocol substream twice |
| CVE-2026-34065 | 7.5 HIGH | nimiq-primitives: Node crash due to missing interlink validation in election macro block p |
| CVE-2026-34068 | 6.8 MEDIUM | nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of- |
| CVE-2026-34062 | 5.3 MEDIUM | Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/respo |
| CVE-2026-34064 | 5.3 MEDIUM | nimiq-account: Vesting insufficient funds error can panic |
| CVE-2026-34066 | 5.3 MEDIUM | nimiq-blockchain: Peer-triggerable panic during history sync |
No comments yet