Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nimiq

First CVE: Feb 27, 2026Active for: 1 yearTotal CVEs: 15
39.5
VTI Score
Medium

Nimiq operates a modestly represented blockchain and proof-of-stake platform, with its vulnerability footprint concentrated in core consensus and staking components such as its Proof of Stake protocol and Albatross consensus implementation. The recurring weakness classes—reachable assertions, input-validation gaps, integer underflow conditions, and insufficient data-authenticity verification—are characteristic of consensus-critical codebases where logic flaws and boundary conditions can have outsized impact on protocol integrity and state consistency. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
15.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nimiq over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 27, 2026
4 months ago
Most Recent CVE
Apr 22, 2026
93 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33471CRITICAL
nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` ind
Apr 22, 20269.633NONO
CVE-2026-40093HIGH
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for
Apr 9, 20268.128NONO
CVE-2026-35468HIGH
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus
Apr 3, 20267.528NONO
CVE-2026-34065HIGH
nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node t
Apr 22, 20267.526NONO
CVE-2026-34064HIGH
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::Insufficie
Apr 22, 20268.226NONO
CVE-2026-34063HIGH
Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the ha
Apr 22, 20267.526NONO
CVE-2026-32605HIGH
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an untrusted peer could cr
Apr 13, 20267.526NONO
CVE-2026-33184HIGH
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, the discovery handler acce
Apr 3, 20267.525NONO
CVE-2026-28402HIGH
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised
Feb 27, 20267.124NONO
CVE-2026-34068MEDIUM
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions
Apr 22, 20266.822NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
40%
53%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High2 (13.3%)
Unknown0 (0.0%)
User Interaction
None13 (86.7%)
Unknown0 (0.0%)
Required2 (13.3%)
Privileges Required
Low4 (26.7%)
High0 (0.0%)
None11 (73.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nimiq.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nimiq — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nimiq's Products

View all 1 CNAs →

Top CWEs