nimiq-primitives is vulnerable to Denial of Service
73
High Risk
Affected versions are vulnerable to a remote unauthenticated denial-of-service vulnerability in MerkleRadixTrie::put_chunk. A malicious state-sync peer can send a crafted chunk containing an invalid root key item that triggers a panic during trie insertion, causing the node process to crash. The issue affects nodes performing state synchronization with untrusted peers, including newly joining or recovering nodes.
You are affected if you are using a version that falls within the vulnerable range.
nimiq-primitives is vulnerable to Denial of Service in versions 0.0.1 - 1.4.0.
Upgrade the nimiq-primitives library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant