nimiq-keys
Rust implementation of the Albatross protocol
Activity
- Latest release
- 1w ago
- Total releases
- 17
- Cadence
- ~9 days
- Last 12 months
- 14
Reach
- Downloads
- 16.1k
- Stars
- 172
Details
- License
- Apache-2.0
- First release
- Feb 04, 2019
| Version | Released | |
|---|---|---|
2.1.0
minor
|
2.1.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
2.0.0
major
|
2.0.0
major
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.7.2
unknown
|
1.7.2
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.7.1
unknown
|
1.7.1
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.7.0
unknown
|
1.7.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.6.1
unknown
|
1.6.1
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.6.0
unknown
|
1.6.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.5.1
unknown
|
1.5.1
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.5.0
unknown
|
1.5.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.4.0
unknown
|
1.4.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.3.0
unknown
1 CVE
CVE-2026-46542
GHSA-h9cc-w26m-j342
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
ImpactA denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. A secondary panic existed in Who is affected: Browser and desktop wallet users of the web-client WASM library and the Who is NOT affected: Validator nodes, consensus, blockchain, mempool, and networking code. There is no on-chain multisig account type; multisig is a purely client-side construct, and no validator/consensus code calls the multisig delinearization path. PatchesSee PR. WorkaroundsNo code-level workaround exists short of the patch. Users of wallet applications can mitigate exposure by only performing multisig operations with public keys received from trusted sources. Resources
Fixed in
1.4.0
References
Updated Jun 10, 2026 · Source: OSV.dev |
1.3.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.2.2
unknown
1 CVE
CVE-2026-46542
GHSA-h9cc-w26m-j342
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
ImpactA denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. A secondary panic existed in Who is affected: Browser and desktop wallet users of the web-client WASM library and the Who is NOT affected: Validator nodes, consensus, blockchain, mempool, and networking code. There is no on-chain multisig account type; multisig is a purely client-side construct, and no validator/consensus code calls the multisig delinearization path. PatchesSee PR. WorkaroundsNo code-level workaround exists short of the patch. Users of wallet applications can mitigate exposure by only performing multisig operations with public keys received from trusted sources. Resources
Fixed in
1.4.0
References
Updated Jun 10, 2026 · Source: OSV.dev |
1.2.2
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.2.1
unknown
1 CVE
CVE-2026-46542
GHSA-h9cc-w26m-j342
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
ImpactA denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. A secondary panic existed in Who is affected: Browser and desktop wallet users of the web-client WASM library and the Who is NOT affected: Validator nodes, consensus, blockchain, mempool, and networking code. There is no on-chain multisig account type; multisig is a purely client-side construct, and no validator/consensus code calls the multisig delinearization path. PatchesSee PR. WorkaroundsNo code-level workaround exists short of the patch. Users of wallet applications can mitigate exposure by only performing multisig operations with public keys received from trusted sources. Resources
Fixed in
1.4.0
References
Updated Jun 10, 2026 · Source: OSV.dev |
1.2.1
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.2.0
unknown
1 CVE
CVE-2026-46542
GHSA-h9cc-w26m-j342
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
ImpactA denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. A secondary panic existed in Who is affected: Browser and desktop wallet users of the web-client WASM library and the Who is NOT affected: Validator nodes, consensus, blockchain, mempool, and networking code. There is no on-chain multisig account type; multisig is a purely client-side construct, and no validator/consensus code calls the multisig delinearization path. PatchesSee PR. WorkaroundsNo code-level workaround exists short of the patch. Users of wallet applications can mitigate exposure by only performing multisig operations with public keys received from trusted sources. Resources
Fixed in
1.4.0
References
Updated Jun 10, 2026 · Source: OSV.dev |
1.2.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
0.2.0
unknown
2 CVEs
CVE-2026-46542
GHSA-h9cc-w26m-j342
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
ImpactA denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. A secondary panic existed in Who is affected: Browser and desktop wallet users of the web-client WASM library and the Who is NOT affected: Validator nodes, consensus, blockchain, mempool, and networking code. There is no on-chain multisig account type; multisig is a purely client-side construct, and no validator/consensus code calls the multisig delinearization path. PatchesSee PR. WorkaroundsNo code-level workaround exists short of the patch. Users of wallet applications can mitigate exposure by only performing multisig operations with public keys received from trusted sources. Resources
Fixed in
1.4.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-40092
GHSA-27w2-87xv-37c6
May 15, 2026
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactA malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record containing a PatchesThe patch for this vulnerability is formally released as part of v1.4.0. WorkaroundsNo known workarounds. ResourcesSee PR. References
Updated Jun 08, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.1.0
unknown
2 CVEs
CVE-2026-46542
GHSA-h9cc-w26m-j342
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
ImpactA denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. A secondary panic existed in Who is affected: Browser and desktop wallet users of the web-client WASM library and the Who is NOT affected: Validator nodes, consensus, blockchain, mempool, and networking code. There is no on-chain multisig account type; multisig is a purely client-side construct, and no validator/consensus code calls the multisig delinearization path. PatchesSee PR. WorkaroundsNo code-level workaround exists short of the patch. Users of wallet applications can mitigate exposure by only performing multisig operations with public keys received from trusted sources. Resources
Fixed in
1.4.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-40092
GHSA-27w2-87xv-37c6
May 15, 2026
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactA malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record containing a PatchesThe patch for this vulnerability is formally released as part of v1.4.0. WorkaroundsNo known workarounds. ResourcesSee PR. References
Updated Jun 08, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
0.0.0
unknown
2 CVEs
CVE-2026-46542
GHSA-h9cc-w26m-j342
May 21, 2026
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
4.3
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
Low
ImpactA denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. A secondary panic existed in Who is affected: Browser and desktop wallet users of the web-client WASM library and the Who is NOT affected: Validator nodes, consensus, blockchain, mempool, and networking code. There is no on-chain multisig account type; multisig is a purely client-side construct, and no validator/consensus code calls the multisig delinearization path. PatchesSee PR. WorkaroundsNo code-level workaround exists short of the patch. Users of wallet applications can mitigate exposure by only performing multisig operations with public keys received from trusted sources. Resources
Fixed in
1.4.0
References
Updated Jun 10, 2026 · Source: OSV.dev
CVE-2026-40092
GHSA-27w2-87xv-37c6
May 15, 2026
nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactA malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record containing a PatchesThe patch for this vulnerability is formally released as part of v1.4.0. WorkaroundsNo known workarounds. ResourcesSee PR. References
Updated Jun 08, 2026 · Source: OSV.dev |