CVE-2026-34063General(nimiq / nimiq_proof-of-stake)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nimiq nimiq_proof-of-stake systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there is at most one inbound and one outbound discovery substream per connection. if a remote peer opens/negotiate the discovery protocol substream a second time on the same connection, the handler hits a `panic!(\"Inbound already connected\")` / `panic!(\"Outbound already connected\")` path instead of failing closed. This causes a remote crash of the networking task (swarm), taking the node's p2p networking offline until restart. The patch for this vulnerability is formally released as part of v1.3.0. No known workarounds are available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nimiq_proof-of-stake

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
nimiq_proof-of-stake

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-23: 2Patch / Workaround · 2026-04-23: 104-23
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34063 Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state m… https://www.cve.org/CVERecord?id=CVE-2026-34063 ----- Traducción: CVE-2026-34063 La … http://infoflow.cloud`

    Post summary

    The post simply announces CVE-2026-34063 and provides a link to the CVE record, offering no further detail or actionable information.

    0000056
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34063 Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state m… https://www.cve.org/CVERecord?id=CVE-2026-34063

    Post summary

    The post references CVE‑2026‑34063 and notes that version 1.3.0 of Nimiq’s network-libp2p presumably contains a patch, but offers no other technical details, PoC, or exploitation evidence.

    00000130
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnimiqnimiq_proof-of-stake-rust-

Explore more