Remote Crash Vulnerability in Nimiq Protocol by Nimiq
CVE-2026-46543

5.3MEDIUM

Key Information:

Vendor

Nimiq

Vendor
CVE Published:
9 June 2026

What is CVE-2026-46543?

A vulnerability in the Nimiq Proof-of-Stake protocol allows remote attackers to crash full nodes by sending a RequestBatchSet message that includes the genesis block's hash. This issue arises during the processing of epoch chunks, where a panic occurs if it attempts to access macro blocks before the genesis block. To mitigate this risk, users are advised to upgrade to version 1.5.0, which contains the necessary patch.

Affected Version(s)

core-rs-albatross < 1.5.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.