Nimiq's software components contain vulnerabilities that could allow remote peers to cause nodes to panic or exploit weaknesses in the system.
Claims
Nimiq's software components contain vulnerabilities that could allow remote peers to cause nodes to panic or exploit weaknesses in the system.
Parent: BlockchainEntity: NimiqSub-entity: Software ComponentsImpact: negativeDate: Apr 23, 2026Target: Nimiq's software components contain vulnerabilities that could allow remote peers to cause nodes to panic or exploit weaknesses in the system.
Source posts
๐จ EUVD-2026-25056
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: network-libp2p
๐ข Vendor: nimiq
๐
Updated: 2026-04-22
๐ nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer can send only a partial frame and keep the substream op...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25056
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25058
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: network-libp2p
๐ข Vendor: nimiq
๐
Updated: 2026-04-22
๐ Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there is at most one inbound and one outbound discovery sub...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25058
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25054
๐ Score: 9.6/10 (CVSS v3.1)
๐ฆ Product: nimiq-block
๐ข Vendor: nimiq
๐
Updated: 2026-04-22
๐ nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each `usize` index to `u16` (`slot as u16`) for slot lookup. ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25054
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25062
๐ Score: 7.5/10 (CVSS v3.1)
๐ฆ Product: nimiq-primitives
๐ข Vendor: nimiq
๐
Updated: 2026-04-22
๐ nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announcing an election macro block whose `validators` set co...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25062
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-25064
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: nimiq-blockchain
๐ข Vendor: nimiq
๐
Updated: 2026-04-22
๐ nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStore::put_historic_txns` uses an `assert!` to enforce invariants about `HistoricTransaction.block_number` (must be within the macro bl...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25064
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability