Intel

AIKIDO-2026-10905

nimiq-blockchain is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data AuthenticityCVE-2026-34061 Published 6 days ago

49

Medium Risk

This Affects:

RUSTnimiq-blockchain
0.0.1 - 1.2.2
Fixed in 1.3.0
Are you affected? Scan for Free

TL;DR

Affected versions are vulnerable to a consensus validation flaw in election macro block proposal verification. A malicious validator proposer can submit an election macro block with an invalid interlink that passes proposal validation and receives prevotes and precommits, but is later rejected during final block verification, potentially causing consensus disruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nimiq-blockchain is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 1.2.2.

How to fix this

Upgrade the nimiq-blockchain library to the patch version.