nimiq-blockchain
Activity
- Latest release
- 6y ago
- Total releases
- 3
- Cadence
- ~5 months
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Feb 04, 2019
| Version | Released | |
|---|---|---|
0.2.0
unknown
4 CVEs
CVE-2026-46369
GHSA-3763-qp59-59vf
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe validity store treats a transaction with stored Patcheshttps://github.com/nimiq/core-rs-albatross/pull/3772 WorkaroundsNo known workarounds Fixed in
1.5.1
References Updated Aug 12, 2026 · Source: OSV.dev
CVE-2026-46543
GHSA-vghx-352f-93jm
May 21, 2026
nimiq-blockchain: Genesis batch set request
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls PatchesThe patch for this vulnerability is formally released as part of v1.5.0. WorkaroundsNo Workaround, although requesting the genesis batch set is not used during normal operation. ResourcesSee PR. Fixed in
1.5.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-34066
GHSA-j99g-7rqw-q9jg
Apr 22, 2026
nimiq-blockchain: Peer-triggerable panic during history sync
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
Impact
PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds. References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40093
GHSA-49xc-52mp-cc9j
Apr 10, 2026
nimiq-blockchain is missing a wall-clock upper bound on block timestamps
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
ImpactBlock timestamp validation enforces that PatchesTBD WorkaroundsNo know workarounds. References Updated Apr 10, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (19)
+ 11 more |
|
0.1.0
unknown
4 CVEs
CVE-2026-46369
GHSA-3763-qp59-59vf
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe validity store treats a transaction with stored Patcheshttps://github.com/nimiq/core-rs-albatross/pull/3772 WorkaroundsNo known workarounds Fixed in
1.5.1
References Updated Aug 12, 2026 · Source: OSV.dev
CVE-2026-46543
GHSA-vghx-352f-93jm
May 21, 2026
nimiq-blockchain: Genesis batch set request
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls PatchesThe patch for this vulnerability is formally released as part of v1.5.0. WorkaroundsNo Workaround, although requesting the genesis batch set is not used during normal operation. ResourcesSee PR. Fixed in
1.5.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-34066
GHSA-j99g-7rqw-q9jg
Apr 22, 2026
nimiq-blockchain: Peer-triggerable panic during history sync
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
Impact
PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds. References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40093
GHSA-49xc-52mp-cc9j
Apr 10, 2026
nimiq-blockchain is missing a wall-clock upper bound on block timestamps
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
ImpactBlock timestamp validation enforces that PatchesTBD WorkaroundsNo know workarounds. References Updated Apr 10, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (19)
+ 11 more |
|
0.0.0
unknown
4 CVEs
CVE-2026-46369
GHSA-3763-qp59-59vf
Aug 12, 2026
nimiq-blockchain: Validity store off by one error
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
ImpactThe validity store treats a transaction with stored Patcheshttps://github.com/nimiq/core-rs-albatross/pull/3772 WorkaroundsNo known workarounds Fixed in
1.5.1
References Updated Aug 12, 2026 · Source: OSV.dev
CVE-2026-46543
GHSA-vghx-352f-93jm
May 21, 2026
nimiq-blockchain: Genesis batch set request
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
ImpactA remote peer can crash any full node by sending a RequestBatchSet message containing the genesis block's hash. The handler calls PatchesThe patch for this vulnerability is formally released as part of v1.5.0. WorkaroundsNo Workaround, although requesting the genesis batch set is not used during normal operation. ResourcesSee PR. Fixed in
1.5.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-34066
GHSA-j99g-7rqw-q9jg
Apr 22, 2026
nimiq-blockchain: Peer-triggerable panic during history sync
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
None
None
High
Impact
PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds. References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40093
GHSA-49xc-52mp-cc9j
Apr 10, 2026
nimiq-blockchain is missing a wall-clock upper bound on block timestamps
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
ImpactBlock timestamp validation enforces that PatchesTBD WorkaroundsNo know workarounds. References Updated Apr 10, 2026 · Source: OSV.dev |
0.0.0
unknown
|