OVERVIEW CVE-2026-34064 is a denial-of-service vulnerability in nimiq-account versions prior to 1.3.0, a Rust library containing account primitives for the Nimiq blockchain implementation. The flaw exists in the VestingContract::can_change_balance function, which can be triggered to cause a node crash when processing vesting contracts with improperly validated parameters. SEVERITY The vulnerability has a CVSS 3.1 score of 5.3 (Medium) with a network-based attack vector requiring no privileges or user interaction. An attacker can exploit this by creating a malicious vesting contract that encodes a total_amount exceeding the actual transaction value, then broadcasting an outgoing transaction to trigger an integer underflow panic during either mempool admission or block processing. While the attack is straightforward to execute with low complexity, the impact is limited to availability disruption rather than data confidentiality or integrity compromise. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, with the vulnerability remaining inactive on security tracking lists. No public exploit code is currently available, and community attention appears minimal. The EPSS probability score of 0.00029 indicates very low likelihood of exploitation attempts relative to the broader CVE landscape. Patched version 1.3.0 has been released with no known workarounds available prior to upgrading.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:nimiq:nimiq_proof-of-stake:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.