PT-2026-48332 · Nimiq · Core-Rs-Albatross

Published

2026-06-09

·

Updated

2026-06-10

·

CVE-2026-46541

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, iIn handle dht get(), the DhtResults accumulator is only initialized when the first DHT record passes verification. If the first record fails (from a malicious DHT node), DhtResults is never created, and all subsequent valid records are discarded with "DHT inconsistent state" errors. This issue has been patched in version 1.4.0.

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2026-46541

Affected Products

Core-Rs-Albatross