CVE-2026-34065Disclosure(nimiq / nimiq_proof-of-stake)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nimiq nimiq_proof-of-stake systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announcing an election macro block whose `validators` set contains an invalid compressed BLS voting key. Hashing an election macro header hashes `validators` and reaches `Validators::voting_keys()`, which calls `validator.voting_key.uncompress().unwrap()` and panics on invalid bytes. The patch for this vulnerability is included as part of v1.3.0. No known workarounds are available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-252CWE-755

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nimiq_proof-of-stake

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
nimiq_proof-of-stake

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-23: 1Patch / Workaround · 2026-04-23: 104-23
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-34065 nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can … https://www.cve.org/CVERecord?id=CVE-2026-34065

    Post summary

    The text announces CVE‑2026‑34065 in Nimiq’s Rust primitives, noting that untrusted peers pose a risk before v1.3.0, but provides no PoC, exploit details, or active‑exploitation evidence.

    00000123
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnimiqnimiq_proof-of-stake-rust-

Explore more