Replay Attack Vulnerability in Nimiq Proof-of-Stake Protocol by Nimiq
CVE-2026-46369
7.5HIGH
What is CVE-2026-46369?
A vulnerability in the Nimiq Proof-of-Stake protocol's validity store from version 1.5.0 allows remote attackers to exploit a timing issue. This occurs due to a strict lower-bound comparison that invalidates a stored transaction prematurely, enabling attackers to replay signed transactions within a narrow window. As a result, both sender and recipient balances can be manipulated, leading to double spending of transactions. This issue has been addressed in version 1.5.1.
Affected Version(s)
core-rs-albatross < 1.5.1
