Description
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk whose proof contains a TrieNodeChild suffix that is individually valid but exceeds the 63-byte KeyNibbles backing array when combined with the parent key. KeyNibbles::Add in primitives/src/key_nibbles.rs performs the combined slice operation without checking the total length, and the input reaches put_chunk, TrieNodeChild::key, and TrieNodeChild::is_stump before proof.verify, so the attacker does not need a valid cryptographic proof. Exploitation requires the attacker to be selected as the victim's sync peer during state sync. The resulting out-of-bounds panic is transient because the node restarts and resynchronizes. This issue is fixed in version 1.6.0.
Published: 2026-09-14
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Out‑of‑Bounds Panic Crash
Action: Patch Now
AI Analysis

Impact

A malicious node that becomes the state‑sync peer can send a specially crafted TrieChunk. The calculation is not verified because the vulnerability does not require a valid cryptographic proof. When the node processes the TrieChunk, the KeyNibbles::Add routine adds a child suffix that, when combined with the parent key, exceeds the 63‑byte array allocated for key nibbles. At that point the routine panics and the node crashes. The crash is temporary; the node restarts and continues synchronization. No confidential data is leaked and the attacker does not gain persistent control.

Affected Systems

Affected systems are the Nimiq core‑rs‑albatross implementation of the Albatross consensus protocol. Version 1.5.x and any earlier releases contain the flaw; the problem was fixed in release v1.6.0. Only the Rust implementation is affected; no other vendors or products are listed.

Risk and Exploitability

The risk score is CVSS 3.7, which indicates low severity. The EPSS score of less than 1 % shows that real‑world exploitation is very unlikely. The vulnerability is not listed in the CISA KEV catalog. The only attack path is a state‑sync session where the attacker is selected as the victim’s sync peer; no additional credentials or privileges are required. The impact is limited to a temporary crash and restart at the target node, with no direct data theft or persistence of attacker influence.

Generated by OpenCVE AI on September 21, 2026 at 01:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade core‑rs‑albatross to v1.6.0 or later.
  • Configure the node to accept state‑sync connections only from trusted, authenticated peers or block unknown peers through firewall rules.
  • Enable log monitoring for panic events and node restarts to detect potential exploit attempts.

Generated by OpenCVE AI on September 21, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5rg2-xv9j-gv5p nimiq-primitives: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof
History

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Nimiq
Nimiq core-rs-albatross
Vendors & Products Nimiq
Nimiq core-rs-albatross

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk whose proof contains a TrieNodeChild suffix that is individually valid but exceeds the 63-byte KeyNibbles backing array when combined with the parent key. KeyNibbles::Add in primitives/src/key_nibbles.rs performs the combined slice operation without checking the total length, and the input reaches put_chunk, TrieNodeChild::key, and TrieNodeChild::is_stump before proof.verify, so the attacker does not need a valid cryptographic proof. Exploitation requires the attacker to be selected as the victim's sync peer during state sync. The resulting out-of-bounds panic is transient because the node restarts and resynchronizes. This issue is fixed in version 1.6.0.
Title Nimiq: Out-of-bounds panic in KeyNibbles::Add from oversized child suffix in a deserialized proof
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Nimiq Core-rs-albatross
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:07:10.225Z

Reserved: 2026-06-15T19:04:14.455Z

Link: CVE-2026-54542

cve-icon Vulnrichment

Updated: 2026-09-14T19:20:58.932Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:12.377

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:30:08Z

Weaknesses