OVERVIEW CVE-2026-40093 affects nimiq-blockchain version 1.3.0 and earlier, the persistent block storage component for Nimiq's Rust blockchain implementation. The vulnerability exists in block timestamp validation logic, which fails to enforce an upper bound check against the current wall clock time. This allows malicious block-producing validators to set block timestamps arbitrarily far into the future, bypassing intended temporal constraints. SEVERITY The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low privileges and minimal complexity. While confidentiality is not impacted, the flaw enables high-integrity and high-availability attacks. The malicious timestamp manipulation directly affects critical reward calculation functions in the blockchain's reward system, enabling attackers to artificially inflate the monetary supply beyond the intended emission schedule and compromise economic parameters. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on exploit alert lists. No public exploit code is currently documented. The EPSS score of 0.00066 indicates this remains a low-probability exploitation target relative to other CVEs, though the moderate FAUCET Risk Score of 49.0 warrants attention from affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:nimiq:nimiq_proof-of-stake:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.