|
2161
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announci…
|
CWE-252 CWE-755
Unchecked Return Value Improper Handling of Exceptional Conditions
|
CVE-2026-34065
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2162
|
8.2 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-34064
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2163
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there…
|
CWE-617
Reachable Assertion
|
CVE-2026-34063
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2164
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer c…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-34062
|
2026-04-25 02:11 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2165
|
9.6 |
CRITICAL
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each…
|
CWE-20 CWE-190 CWE-345 CWE-1284
Improper Input Validation Integer Overflow or Wraparound Insufficient Verification of Data Authenticity Improper Validation of Specified Quantity in Input
|
CVE-2026-33471
|
2026-04-25 02:11 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2166
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an untrusted peer could crash a validator by …
|
CWE-125 CWE-193
Out-of-bounds Read Off-by-one Error
|
CVE-2026-32605
|
2026-04-25 02:11 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2167
|
8.1 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for non-skip blocks an…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-40093
|
2026-04-25 02:11 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2168
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. In versions 1.2.2 and below, an unauthenticated p2p peer can cause th…
|
CWE-617
Reachable Assertion
|
CVE-2026-34069
|
2026-04-25 02:10 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2169
|
6.8 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_votin…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-34068
|
2026-04-25 02:10 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2170
|
8.1 |
HIGH
Network
|
sgbett
|
bsv-wallet bsv_ruby_sdk
|
BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificate persists certificate records to storage without verifying the certifier'…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-40070
|
2026-04-25 02:03 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|