Denial-of-Service Vulnerability in Nimiq's Proof-of-Stake Protocol
CVE-2026-46545
7.5HIGH
What is CVE-2026-46545?
A remote, unauthenticated denial-of-service vulnerability was identified in Nimiq's Proof-of-Stake protocol, specifically within the MerkleRadixTrie::put_chunk function. This flaw allows any state-sync peer to crash nodes that are performing state synchronization, particularly affecting freshly joining and recovering nodes. The issue has been effectively mitigated in version 1.5.0.
Affected Version(s)
core-rs-albatross < 1.5.0
