Nimiq operates a modestly represented blockchain and proof-of-stake platform, with its vulnerability footprint concentrated in core consensus and staking components such as its Proof of Stake protocol and Albatross consensus implementation. The recurring weakness classes—reachable assertions, input-validation gaps, integer underflow conditions, and insufficient data-authenticity verification—are characteristic of consensus-critical codebases where logic flaws and boundary conditions can have outsized impact on protocol integrity and state consistency. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nimiq over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33471CRITICAL nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its quorum check using `BitSet.len()`, then iterates `BitSet` ind | Apr 22, 2026 | 9.6 | 33 | NO | NO |
CVE-2026-40093HIGH nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestamp validation enforces that timestamp >= parent.timestamp for | Apr 9, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-35468HIGH nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus | Apr 3, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-34065HIGH nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node t | Apr 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-34064HIGH nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::Insufficie | Apr 22, 2026 | 8.2 | 26 | NO | NO |
CVE-2026-34063HIGH Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the ha | Apr 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-32605HIGH nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an untrusted peer could cr | Apr 13, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-33184HIGH nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, the discovery handler acce | Apr 3, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-28402HIGH nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised | Feb 27, 2026 | 7.1 | 24 | NO | NO |
CVE-2026-34068MEDIUM nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions | Apr 22, 2026 | 6.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nimiq.
Media articles that mention a CVE ID that affects a product developed by Nimiq — matched by CVE ID, not by vendor name.