โ† All reports

Nimiq's software components contain vulnerabilities that could allow remote peers to cause nodes to panic or exploit weaknesses in the system.

CybersecurityTechnologyConflictBlockchainApr 23, 2026score 0.175 posts ยท 0 replies across 1 instances
This thread discusses multiple vulnerabilities in Nimiq's software components, including issues with block verification, network discovery, message handling, block storage, and election macro blocks. These vulnerabilities could allow remote peers to cause panics or exploit weaknesses in the system, highlighting security concerns in the Nimiq network.

Claims

Nimiq's software components contain vulnerabilities that could allow remote peers to cause nodes to panic or exploit weaknesses in the system.
Parent: BlockchainEntity: NimiqSub-entity: Software ComponentsImpact: negativeDate: Apr 23, 2026Target: Nimiq's software components contain vulnerabilities that could allow remote peers to cause nodes to panic or exploit weaknesses in the system.

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-25056 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: network-libp2p ๐Ÿข Vendor: nimiq ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer can send only a partial frame and keep the substream op... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25056 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25058 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: network-libp2p ๐Ÿข Vendor: nimiq ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there is at most one inbound and one outbound discovery sub... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25058 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25054 ๐Ÿ“Š Score: 9.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: nimiq-block ๐Ÿข Vendor: nimiq ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each `usize` index to `u16` (`slot as u16`) for slot lookup. ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25054 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25062 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: nimiq-primitives ๐Ÿข Vendor: nimiq ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announcing an election macro block whose `validators` set co... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25062 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-25064 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: nimiq-blockchain ๐Ÿข Vendor: nimiq ๐Ÿ“… Updated: 2026-04-22 ๐Ÿ“ nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStore::put_historic_txns` uses an `assert!` to enforce invariants about `HistoricTransaction.block_number` (must be within the macro bl... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25064 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 23, 2026
#cybersecurity#infosec#euvd#cve#vulnerability