Intel

AIKIDO-2026-10904

nimiq-block is vulnerable to Integer Overflow

Integer OverflowCVE-2026-33471 Published 6 days ago

96

Critical Risk

This Affects:

RUSTnimiq-block
0.0.1 - 1.2.2
Fixed in 1.3.0
Are you affected? Scan for Free

TL;DR

Affected versions are vulnerable to an authentication bypass issue in SkipBlockProof::verify caused by improper handling of out-of-range BitSet indices. An attacker can craft signer indices that inflate quorum calculations while mapping to the same validator slot after type casting, potentially allowing a malicious validator with insufficient real signatures to forge a valid skip block proof.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nimiq-block is vulnerable to Integer Overflow in versions 0.0.1 - 1.2.2.

How to fix this

Upgrade the nimiq-block library to the patch version.