Vulnerabilities in nimiq

25 results
CVE-2026-40092HIGHnimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHTEPSS 0.6%CVE-2025-47270HIGHnimiq-network-libp2p Uncontrolled Resource Consumption vulnerabilityEPSS 0.6%CVE-2026-35468MEDIUMnimiq/core-rs-albatross: Panic in history index request handlers when a full node runs without the history indexEPSS 0.5%CVE-2026-32605HIGHNimiq: Remote crash via off-by-one signer bounds check in proposal bufferEPSS 0.5%CVE-2026-33184HIGHnimiq/core-rs-albatross: Discovery handshake limit could underflow and later provoke a deterministic overflow panicEPSS 0.5%CVE-2026-34065HIGHnimiq-primitives: Node crash due to missing interlink validation in election macro block proposalsEPSS 0.4%CVE-2026-34063HIGHnetwork-libp2p: Peer can crash the node by opening discovery protocol substream twiceEPSS 0.4%CVE-2026-46541HIGHNimiq network-libp2p: DHT query poisoning via first-record verification failureEPSS 0.3%CVE-2026-46545HIGHnimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed itemEPSS 0.3%CVE-2026-34067LOWnimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatchEPSS 0.3%CVE-2026-40093HIGHnimiq-blockchain is missing a wall-clock upper bound on block timestampsEPSS 0.3%CVE-2026-40094MEDIUMnimiq-blockchain: network-libp2p untrusted peer can crash address book via empty peer contact addressesEPSS 0.3%CVE-2026-34062MEDIUMNimiq has Allocation of Resources Without Limits or Throttling in its libp2p request/responseEPSS 0.3%CVE-2026-34069MEDIUMnimiq-consensus panics via RequestMacroChain micro-block locatorEPSS 0.3%CVE-2026-44505MEDIUMNimiq network-libp2p: Untrusted peer can wedge DHTEPSS 0.3%CVE-2026-46543MEDIUMnimiq-blockchain: Genesis batch set requestEPSS 0.3%CVE-2026-34064MEDIUMnimiq-account: Vesting insufficient funds error can panicEPSS 0.3%CVE-2026-46540MEDIUMNimiq light-blockchain: Light blockchain rebranch issueEPSS 0.3%CVE-2026-34066MEDIUMnimiq-blockchain: Peer-triggerable panic during history syncEPSS 0.2%CVE-2026-46542MEDIUMnimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve pointsEPSS 0.2%