nimiq-primitives
crates.io5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting nimiq-primitivespage 1 of 1
- CVE-2026-34065HIGHCVSS 7.5EG 7.52026-04-22
nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announcing an election macro block whose `valida…
- CVE-2026-46539MEDIUMCVSS 5.9EG 5.92026-05-21
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven causes the function to return true without perform…
- CVE-2026-46545HIGHCVSS 7.5EG 7.5✓ Fixed in 1.5.02026-05-21
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote, unauthenticated denial-of-service vulnerability in MerkleRadixTrie::put_chunk allows any stat…
- CVE-2026-54541LOWCVSS 3.7EG 3.7✓ Fixed in 1.6.02026-07-16
nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys ### Impact A malicious peer acting as a state-sync source can crash a syncing node by sending a crafted `TrieChunk` whose proof contains two `TriePr…
- CVE-2026-54542LOWCVSS 3.7EG 3.7✓ Fixed in 1.6.02026-07-16
nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof ### Impact A malicious peer acting as a state-sync source can crash a syncing node with a crafted `TrieChunk` whose proof contai…
Check whether nimiq-primitives is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for nimiq-primitives CVEs against the assets you own.
Start Free Scan →