← Volver al buscador de CVEs

CVE-2026-46539

Nimiq

Descripción

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven causes the function to return true without performing any cryptographic verification when get_interlink_hops yields an empty hop list. This occurs when the target block is at the election block position immediately preceding the election head-s epoch. An attacker providing transaction inclusion proofs can forge a MacroBlock header for that epoch position and have it accepted as -proven- without any hash or signature verification. This issue has been patched in version 1.4.0.

CVSS 5.9EPSS 0.15%Riesgo 0.6
Ver fuente
Publicación
2026-06-10 00:16:54
Versiones afectadas
<1.4.0
Tipo
Software crítico
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N