Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7c4j-2m43-2mgh | nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals |
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nimiq nimiq-primitives
|
|
| Vendors & Products |
Nimiq nimiq-primitives
|
Fri, 24 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nimiq
Nimiq nimiq Proof-of-stake |
|
| CPEs | cpe:2.3:a:nimiq:nimiq_proof-of-stake:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Nimiq
Nimiq nimiq Proof-of-stake |
Thu, 23 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announcing an election macro block whose `validators` set contains an invalid compressed BLS voting key. Hashing an election macro header hashes `validators` and reaches `Validators::voting_keys()`, which calls `validator.voting_key.uncompress().unwrap()` and panics on invalid bytes. The patch for this vulnerability is included as part of v1.3.0. No known workarounds are available. | |
| Title | nimiq-primitives: Node crash due to missing interlink validation in election macro block proposals | |
| Weaknesses | CWE-252 CWE-755 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-23T14:17:01.654Z
Reserved: 2026-03-25T16:21:40.867Z
Link: CVE-2026-34065
Updated: 2026-04-23T14:16:57.873Z
Status : Analyzed
Published: 2026-04-22T20:16:41.077
Modified: 2026-04-24T17:12:37.357
Link: CVE-2026-34065
No data.
OpenCVE Enrichment
Updated: 2026-04-28T15:30:34Z
Github GHSA