Impact
A malicious node that becomes the state‑sync peer can send a specially crafted TrieChunk. The calculation is not verified because the vulnerability does not require a valid cryptographic proof. When the node processes the TrieChunk, the KeyNibbles::Add routine adds a child suffix that, when combined with the parent key, exceeds the 63‑byte array allocated for key nibbles. At that point the routine panics and the node crashes. The crash is temporary; the node restarts and continues synchronization. No confidential data is leaked and the attacker does not gain persistent control.
Affected Systems
Affected systems are the Nimiq core‑rs‑albatross implementation of the Albatross consensus protocol. Version 1.5.x and any earlier releases contain the flaw; the problem was fixed in release v1.6.0. Only the Rust implementation is affected; no other vendors or products are listed.
Risk and Exploitability
The risk score is CVSS 3.7, which indicates low severity. The EPSS score of less than 1 % shows that real‑world exploitation is very unlikely. The vulnerability is not listed in the CISA KEV catalog. The only attack path is a state‑sync session where the attacker is selected as the victim’s sync peer; no additional credentials or privileges are required. The impact is limited to a temporary crash and restart at the target node, with no direct data theft or persistence of attacker influence.
OpenCVE Enrichment
Github GHSA