VendorsNimiqnimiq_proof-of-stakeall versions
Vulnerabilities

Nimiq Proof of Stake (core-rs-albatross)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-33471
nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
Published 2026-04-22 · Analyzed
9.6EPSS 0.003
CVE-2026-34064
nimiq-account: Vesting insufficient funds error can panic
Published 2026-04-22 · Analyzed
8.2EPSS 0.005
CVE-2026-40093
nimiq-blockchain is missing a wall-clock upper bound on block timestamps
Published 2026-04-09 · Analyzed
8.1EPSS 0.004
CVE-2026-33184
nimiq/core-rs-albatross: Discovery handshake limit could underflow and later provoke a deterministic overflow panic
Published 2026-04-03 · Analyzed
7.5EPSS 0.006
CVE-2026-35468
nimiq/core-rs-albatross: Panic in history index request handlers when a full node runs without the history index
Published 2026-04-03 · Analyzed
7.5EPSS 0.006
CVE-2026-32605
Nimiq: Remote crash via off-by-one signer bounds check in proposal buffer
Published 2026-04-13 · Analyzed
7.5EPSS 0.006
CVE-2026-34063
network-libp2p: Peer can crash the node by opening discovery protocol substream twice
Published 2026-04-22 · Analyzed
7.5EPSS 0.006
CVE-2026-34065
nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals
Published 2026-04-22 · Analyzed
7.5EPSS 0.006
CVE-2026-28402
nimiq/core-rs-albatross's nimiq-blockchain missing proposal body root verification
Published 2026-02-27 · Analyzed
7.1EPSS 0.003
CVE-2026-34068
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
Published 2026-04-22 · Analyzed
6.8EPSS 0.003
CVE-2026-34067
nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch
Published 2026-04-22 · Analyzed
6.5EPSS 0.004
CVE-2026-34061
nimiq/core-rs-albatross: Macro block proposal interlink bug
Published 2026-04-03 · Analyzed
6.5EPSS 0.003
CVE-2026-34069
nimiq-consensus panics via RequestMacroChain micro-block locator
Published 2026-04-13 · Analyzed
5.3EPSS 0.005
CVE-2026-34062
Nimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/response
Published 2026-04-22 · Analyzed
5.3EPSS 0.005
CVE-2026-34066
nimiq-blockchain: Peer-triggerable panic during history sync
Published 2026-04-22 · Analyzed
5.3EPSS 0.004