Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

nimiq — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting nimiq. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nimiq is a blockchain platform focused on enabling peer-to-peer transactions without centralized infrastructure. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 16 recorded CVEs. The platform's security characteristics include its lightweight JavaScript-based implementation, though this has also introduced attack surfaces. Notable incidents include multiple RCE vulnerabilities in its node software that allowed attackers to execute arbitrary code, and XSS issues in its web wallet components. These vulnerabilities have primarily stemmed from input validation failures and insecure deserialization, highlighting ongoing challenges in securing decentralized applications.

CVE ID Title CVSS Severity Published
CVE-2026-46545 nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item — core-rs-albatross CWE-248 7.5 High 2026-06-09
CVE-2026-46543 nimiq-blockchain: Genesis batch set request — core-rs-albatross CWE-617 5.3 Medium 2026-06-09
CVE-2026-46542 nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points — core-rs-albatross CWE-617 4.3 Medium 2026-06-09
CVE-2026-46541 Nimiq network-libp2p: DHT query poisoning via first-record verification failure — core-rs-albatross CWE-754 7.5 High 2026-06-09
CVE-2026-46540 Nimiq light-blockchain: Light blockchain rebranch issue — core-rs-albatross CWE-841 6.5 Medium 2026-06-09
CVE-2026-46539 nimiq-primitives: BlockInclusionProof interlink issue when hops are empty — core-rs-albatross CWE-345 5.9 Medium 2026-06-09
CVE-2026-44505 Nimiq network-libp2p: Untrusted peer can wedge DHT — core-rs-albatross CWE-755 5.3 Medium 2026-06-09
CVE-2026-40094 nimiq-blockchain: network-libp2p untrusted peer can crash address book via empty peer contact addresses — core-rs-albatross CWE-754 4.3 Medium 2026-05-20
CVE-2026-40092 nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT — core-rs-albatross CWE-252 7.5 High 2026-05-20
CVE-2026-34068 nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge — nimiq-transaction CWE-347 6.8 Medium 2026-04-22
CVE-2026-34067 nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch — nimiq-transaction CWE-617 3.1 Low 2026-04-22
CVE-2026-34066 nimiq-blockchain: Peer-triggerable panic during history sync — nimiq-blockchain CWE-20 5.3 Medium 2026-04-22
CVE-2026-34065 nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals — nimiq-primitives CWE-252 7.5 High 2026-04-22
CVE-2026-34064 nimiq-account: Vesting insufficient funds error can panic — nimiq-account CWE-191 5.3 Medium 2026-04-22
CVE-2026-34063 network-libp2p: Peer can crash the node by opening discovery protocol substream twice — network-libp2p CWE-617 7.5 High 2026-04-22
CVE-2026-34062 Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response — network-libp2p CWE-770 5.3 Medium 2026-04-22
CVE-2026-33471 nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation — nimiq-block CWE-20 9.6 Critical 2026-04-22
CVE-2026-34069 nimiq-consensus panics via RequestMacroChain micro-block locator — core-rs-albatross CWE-617 5.3 Medium 2026-04-13
CVE-2026-32605 Nimiq: Remote crash via off-by-one signer bounds check in proposal buffer — core-rs-albatross CWE-125 7.5 High 2026-04-13
CVE-2026-40093 nimiq-blockchain is missing a wall-clock upper bound on block timestamps — core-rs-albatross CWE-1284 8.1 High 2026-04-09
CVE-2026-35468 nimiq/core-rs-albatross: Panic in history index request handlers when a full node runs without the history index — core-rs-albatross CWE-252 5.3 Medium 2026-04-03
CVE-2026-33184 nimiq/core-rs-albatross: Discovery handshake limit could underflow and later provoke a deterministic overflow panic — core-rs-albatross CWE-191 7.5 High 2026-04-03
CVE-2026-34061 nimiq/core-rs-albatross: Macro block proposal interlink bug — core-rs-albatross CWE-345 4.9 Medium 2026-04-03
CVE-2026-28402 nimiq/core-rs-albatross's nimiq-blockchain missing proposal body root verification — core-rs-albatross CWE-354 7.1 High 2026-02-27
CVE-2025-47270 nimiq-network-libp2p Uncontrolled Resource Consumption vulnerability — core-rs-albatross CWE-400 7.5 High 2025-05-12

This page lists every published CVE security advisory associated with nimiq. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.