nimiq-transaction
Activity
- Latest release
- 6y ago
- Total releases
- 3
- Cadence
- ~4 months
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Feb 15, 2019
| Version | Released | |
|---|---|---|
0.2.0
unknown
2 CVEs
CVE-2026-34068
GHSA-pf4j-pf3w-95f9
Apr 22, 2026
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
6.8
/ 10
Medium
Network
High
None
None
Changed
None
High
None
ImpactThe staking contract accepts Because tendermint macro block justification verification aggregates validator voting keys and verifies a single aggregated BLS signature against that aggregate public key, a rogue-key voting key in the validator set can allow an attacker to forge a quorum-looking justification while only producing a single signature. While the impact is critical, the exploitability is low: The voting keys are fixed for the epoch, so the attacker would need to know the next epoch validator set (chosen through VRF), which is unlikely. PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds. References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34067
GHSA-264v-m8fm-76jm
Apr 22, 2026
nimiq-transaction: Panic via `HistoryTreeProof` length mismatch
3.1
/ 10
Low
Network
High
None
Required
Unchanged
None
None
Low
Impact
The proof object is derived from untrusted p2p responses ( PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds know. References
Updated May 05, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (10)
+ 2 more |
|
0.1.0
unknown
2 CVEs
CVE-2026-34068
GHSA-pf4j-pf3w-95f9
Apr 22, 2026
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
6.8
/ 10
Medium
Network
High
None
None
Changed
None
High
None
ImpactThe staking contract accepts Because tendermint macro block justification verification aggregates validator voting keys and verifies a single aggregated BLS signature against that aggregate public key, a rogue-key voting key in the validator set can allow an attacker to forge a quorum-looking justification while only producing a single signature. While the impact is critical, the exploitability is low: The voting keys are fixed for the epoch, so the attacker would need to know the next epoch validator set (chosen through VRF), which is unlikely. PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds. References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34067
GHSA-264v-m8fm-76jm
Apr 22, 2026
nimiq-transaction: Panic via `HistoryTreeProof` length mismatch
3.1
/ 10
Low
Network
High
None
Required
Unchanged
None
None
Low
Impact
The proof object is derived from untrusted p2p responses ( PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds know. References
Updated May 05, 2026 · Source: OSV.dev |
0.1.0
unknown
Dependencies (10)
+ 2 more |
|
0.0.0
unknown
2 CVEs
CVE-2026-34068
GHSA-pf4j-pf3w-95f9
Apr 22, 2026
nimiq-transaction: UpdateValidator transactions allows voting key change without proof-of-knowledge
6.8
/ 10
Medium
Network
High
None
None
Changed
None
High
None
ImpactThe staking contract accepts Because tendermint macro block justification verification aggregates validator voting keys and verifies a single aggregated BLS signature against that aggregate public key, a rogue-key voting key in the validator set can allow an attacker to forge a quorum-looking justification while only producing a single signature. While the impact is critical, the exploitability is low: The voting keys are fixed for the epoch, so the attacker would need to know the next epoch validator set (chosen through VRF), which is unlikely. PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds. References
Updated May 05, 2026 · Source: OSV.dev
CVE-2026-34067
GHSA-264v-m8fm-76jm
Apr 22, 2026
nimiq-transaction: Panic via `HistoryTreeProof` length mismatch
3.1
/ 10
Low
Network
High
None
Required
Unchanged
None
None
Low
Impact
The proof object is derived from untrusted p2p responses ( PatchesThe patch for this vulnerability is included as part of v1.3.0. WorkaroundsNo known workarounds know. References
Updated May 05, 2026 · Source: OSV.dev |
0.0.0
unknown
|