Intel

AIKIDO-2026-10906

nimiq-blockchain is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-46543 Published 6 days ago

53

Medium Risk

This Affects:

RUSTnimiq-blockchain
0.0.1 - 1.4.0
Fixed in 1.5.0
Are you affected? Scan for Free

TL;DR

Affected versions are vulnerable to a remote denial-of-service issue where a peer can crash a full node by sending a RequestBatchSet message containing the genesis block hash. Processing the request triggers a panic when the code attempts to access a macro block before the genesis block.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nimiq-blockchain is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.4.0.

How to fix this

Upgrade the nimiq-blockchain library to the patch version.