Description
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk proof containing two TrieProofNode values with identical keys. TrieProof::verify calls TrieProofNode::child_index in primitives/src/trie/trie_proof_node.rs, where is_prefix_of accepts equal keys and KeyNibbles::get is called at the key length, returns None, and is unconditionally unwrapped. Untrusted ResponseChunk data reaches commit_chunks, put_chunk, and proof.verify before cryptographic proof validation, so the attacker does not need a valid proof. Exploitation requires the attacker to be selected as the victim's sync peer during state sync, and the resulting panic is transient because the node restarts and resynchronizes. This issue is fixed in version 1.6.0.
Published: 2026-09-14
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A malicious state‑sync peer can crash a syncing node by sending a crafted TrieChunk proof that contains two TrieProofNode values with identical keys. When TrieProof::verify processes the equal‑length keys, it calls TrieProofNode::child_index, which accepts equal keys as prefixes and attempts to retrieve a key slice at full length, yielding None, which is then unconditionally unwrapped. Because untrusted ResponseChunk data is validated before cryptographic proof verification, the attacker does not need a valid proof. The bug causes a transient panic; the node restarts and resynchronizes after the crash.

Affected Systems

The affected product is Nimiq core-rs-albatross, specifically all releases prior to 1.6.0. Version 1.6.0 and later contain a fix that removes the unchecked unwrap.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and the EPSS score is below 1 %. This issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to be selected as the victim’s state‑sync peer during state sync. Once chosen, the attacker can send a malicious proof payload that results in a transient panic. Following the crash, the node automatically restarts and resynchronizes. The attack vector is therefore a network‑based peer‑to‑peer interaction.

Generated by OpenCVE AI on September 20, 2026 at 23:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Nimiq core-rs‑albatross to version 1.6.0 or later.
  • If an upgrade is not immediately possible, configure the nodesync peers cryptographic validation, or use a firewall rule to block known malicious peers.
  • Monitor system logs for panic messages and trigger alerts when such exceptions are recorded.

Generated by OpenCVE AI on September 20, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-46wq-28cx-mhw4 nimiq-primitives: Panic in TrieProof::verify via child_index unwrap on equal-length keys
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Nimiq
Nimiq core-rs-albatross
Vendors & Products Nimiq
Nimiq core-rs-albatross

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk proof containing two TrieProofNode values with identical keys. TrieProof::verify calls TrieProofNode::child_index in primitives/src/trie/trie_proof_node.rs, where is_prefix_of accepts equal keys and KeyNibbles::get is called at the key length, returns None, and is unconditionally unwrapped. Untrusted ResponseChunk data reaches commit_chunks, put_chunk, and proof.verify before cryptographic proof validation, so the attacker does not need a valid proof. Exploitation requires the attacker to be selected as the victim's sync peer during state sync, and the resulting panic is transient because the node restarts and resynchronizes. This issue is fixed in version 1.6.0.
Title Nimiq: Panic in TrieProof::verify via child_index unwrap on equal-length keys
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Nimiq Core-rs-albatross
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:13:43.511Z

Reserved: 2026-06-15T19:04:14.455Z

Link: CVE-2026-54541

cve-icon Vulnrichment

Updated: 2026-09-16T15:13:18.627Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:12.217

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54541

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses