CVE-2026-33471 affects nimiq-block, the block primitives component used in Nimiq's Rust implementation, in versions prior to 1.3.0. The flaw is in SkipBlockProof::verify, which performs quorum validation using BitSet.len() and then iterates signer indices from the bitset while casting each usize index to u16 (slot as u16) for slot lookup during aggregation. Because out-of-range indices separated by 65536 truncate to the same u16 value, an attacker can supply MultiSignature.signers entries that artificially increase the apparent signer count while colliding onto the same valid in-range slot. This breaks the integrity of the quorum check and allows skip block proof verification to succeed even when the proof does not contain the required number of distinct valid signer slots.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
2f+1 quorum requirement for skip block proofs. By inflating the signer count and reusing the same effective slot through usize to u16 truncation, the attacker can make an invalid proof verify as if it had sufficient validator participation. This undermines consensus proof authenticity and can enable acceptance of forged skip block proofs, with high integrity impact and potential availability impact on the protocol or dependent services.If you can’t patch tonight, do this now.
Patch, then assume compromise.
d02059053181ed8ddad6b59a0adfd661ef5cd823.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.