Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-34067— nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch

Quick assessment

Affected
nimiq nimiq-transaction
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nimiq是Nimiq开源的一个Albatross协议的Rust实现。 Nimiq 1.3.0之前版本存在安全漏洞,该漏洞源于nimiq-transaction中HistoryTreeProof::verify在格式错误的证明上触发panic,其中history.len() != positions.len()。证明对象源自不受信任的p2p响应,因此在网络边界上受攻击者控制,直到被验证。恶意对等方可以通过返回长度不匹配的特制包含证明来触发崩溃。

CVSS 3.1 · Low EPSS 0.32% · P25
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-34067

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch
Source: CVE Program / CVE List V5
Vulnerability Description
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` panics on a malformed proof where `history.len() != positions.len()` due to `assert_eq!(history.len(), positions.len())`. The proof object is derived from untrusted p2p responses (`ResponseTransactionsProof.proof`) and is therefore attacker-controlled at the network boundary until validated. A malicious peer could trigger a crash by returning a crafted inclusion proof with a length mismatch. The patch for this vulnerability is included as part of v1.3.0. No known workarounds are available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
可达断言
Source: CVE Program / CVE List V5
Vulnerability Title
Nimiq 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Nimiq是Nimiq开源的一个Albatross协议的Rust实现。 Nimiq 1.3.0之前版本存在安全漏洞,该漏洞源于nimiq-transaction中HistoryTreeProof::verify在格式错误的证明上触发panic,其中history.len() != positions.len()。证明对象源自不受信任的p2p响应,因此在网络边界上受攻击者控制,直到被验证。恶意对等方可以通过返回长度不匹配的特制包含证明来触发崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
nimiq nimiq-transaction < 1.3.0 -

II. Public POCs for CVE-2026-34067

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-34067

登录查看更多情报信息。

Patches & Fixes for CVE-2026-34067 (1)

Vendor Advisories for CVE-2026-34067 (1)

Same Patch Batch · nimiq · 2026-04-22 · 8 CVEs total

CVE-2026-33471 9.6 CRITICAL nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
CVE-2026-34063 7.5 HIGH network-libp2p: Peer can crash the node by opening discovery protocol substream twice
CVE-2026-34065 7.5 HIGH nimiq-primitives: Node crash due to missing interlink validation in election macro block p
CVE-2026-34068 6.8 MEDIUM nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-
CVE-2026-34062 5.3 MEDIUM Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/respo
CVE-2026-34064 5.3 MEDIUM nimiq-account: Vesting insufficient funds error can panic
CVE-2026-34066 5.3 MEDIUM nimiq-blockchain: Peer-triggerable panic during history sync

IV. Related Vulnerabilities

V. Comments for CVE-2026-34067

No comments yet


Leave a comment