CVE-2026-33471Disclosure(nimiq / nimiq_proof-of-stake)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` indices and casts each `usize` index to `u16` (`slot as u16`) for slot lookup. Prior to version 1.3.0, if an attacker can get a `SkipBlockProof` verified where `MultiSignature.signers` contains out-of-range indices spaced by 65536, these indices inflate `len()` but collide onto the same in-range `u16` slot during aggregation. This makes it possible for a malicious validator with far fewer than `2f+1` real signer slots to pass skip block proof verification by multiplying a single BLS signature by the same factor. The patch for this vulnerability is included as part of v1.3.0. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-190CWE-345CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nimiq_proof-of-stake

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-23); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
nimiq_proof-of-stake

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-22: 1Mentions · 2026-04-23: 3Mentions · 2026-04-28: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 3Technical Details · 2026-04-28: 104-2204-2304-28
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-221
Disclosure1
2026-04-233
Disclosure3
2026-04-281
Disclosure1
Full discourse5 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical skip block quorum bypass (CVE-2026-33471) affects `nimiq-block` via out-of-range BitSet indices & u16 truncation. Monitor official `Nimiq` channels for updates. #Blockchain #Nimiq #Infosec https://www.pulsepatch.io/posts/cve-2026-33471-nimiq-block-quorum-bypass

    Post summary

    The tweet announces the discovery of a critical skip block quorum bypass (CVE-2026-33471) in Nimiq‑block, detailing it as caused by out-of-range BitSet indices and u16 truncation, and advises readers to watch official Nimiq channels for updates.

    0001091
    12 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-33471: CVE-2026-33471: Consensus Quorum Bypass via Integer Truncation in Nimiq core-rs-albatross An integer truncation vulnerability in the Nimiq Albatross Proof-of-Stake implementation allows a malicious validator to bypass the 2f+1 consensu... https://cvereports.com/reports/CVE-2026-33471

    Post summary

    The report discloses an integer truncation flaw in Nimiq's Proof‑of‑Stake consensus, allowing a malicious validator to bypass the 2f+1 quorum; no PoC, exploit code, active exploitation, or patch details are provided.

    0000043
    36 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33471 nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterate… https://www.cve.org/CVERecord?id=CVE-2026-33471 ----- Traducción: CVE-2026-33471 nim… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑33471, describing a logic bug in Nimiq’s Rust implementation’s block verification routine, and references the official CVE record, with no PoC, exploit, patch, or active exploitation mentioned.

    0000075
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33471 nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterate… https://www.cve.org/CVERecord?id=CVE-2026-33471

    Post summary

    The post provides a concise disclosure of CVE‑2026‑33471, including a brief technical detail and a link to the official CVE record, without any claim of exploitation or mitigation.

    00000129
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33471: nimiq-block has skip block quoru... Integer overflow in BitSet indexing lets attackers bypass quorum checks with a single BLS signature multiplied by colli... https://zerodaysignal.com/vulnerability/CVE-2026-33471 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-33471, describing an integer overflow in BitSet indexing that allows attackers to bypass quorum checks in nimiq-block using a single BLS signature.

    00000115
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnimiqnimiq_proof-of-stake-rust-

Explore more