Two high-severity vulnerabilities were disclosed in Nimiq's Rust implementation affecting blockchain validation and consensus logic. CVE-2026-40093 impacts nimiq-blockchain version 1.3.0 and earlier because block timestamp validation checks only consistency with the parent block and does not enforce an upper bound against wall-clock time. A malicious block-producing validator can submit blocks dated far into the future, which alters reward calculations in Policy::supply_at() and batch_delay() and can inflate monetary supply beyond the intended emission schedule. The issue was mapped to CWE-1284 and published alongside GitHub advisory GHSA-49xc-52mp-cc9j.
A second flaw, CVE-2026-33471, affects nimiq-block versions prior to 1.3.0 in SkipBlockProof::verify, where quorum validation can be bypassed through out-of-range BitSet indices and u16 truncation. By spacing forged signer indices by 65536, a malicious validator can make multiple entries collide into the same valid slot and effectively reuse a single BLS signature to satisfy skip block proof checks without the required 2f+1 real signer slots. The vulnerability carries no known workaround, and the fix was released in version 1.3.0, highlighting risks to both consensus integrity and chain availability if unpatched nodes remain in use.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry disclosed a high-severity flaw in nimiq-block where SkipBlockProof::verify could be abused to bypass quorum validation by colliding out-of-range signer indices into valid u16 slots. The vulnerability allowed a malicious validator to satisfy verification with fewer than the required 2f+1 real signer slots.
Nimiq released version 1.3.0 to fix a flaw in nimiq-block's SkipBlockProof::verify that allowed out-of-range BitSet indices and u16 truncation to bypass the required skip block quorum. The issue affected versions prior to 1.3.0, and no workaround was noted.
A CVE entry for nimiq-blockchain was published describing a timestamp-validation flaw that let a malicious validator create blocks far in the future, impacting reward calculations and inflating supply beyond the intended emission schedule. GitHub also published the related advisory GHSA-49xc-52mp-cc9j the same day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.