nimiq-block is vulnerable to Integer Overflow
96
Critical Risk
Affected versions are vulnerable to an authentication bypass issue in SkipBlockProof::verify caused by improper handling of out-of-range BitSet indices. An attacker can craft signer indices that inflate quorum calculations while mapping to the same validator slot after type casting, potentially allowing a malicious validator with insufficient real signatures to forge a valid skip block proof.
You are affected if you are using a version that falls within the vulnerable range.
nimiq-block is vulnerable to Integer Overflow in versions 0.0.1 - 1.2.2.
Upgrade the nimiq-block library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant