Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-264v-m8fm-76jm

Опубликовано: 22 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

nimiq-transaction: Panic via HistoryTreeProof length mismatch

Impact

HistoryTreeProof::verify panics on a malformed proof where history.len() != positions.len() due to assert_eq!(history.len(), positions.len()).

The proof object is derived from untrusted p2p responses (ResponseTransactionsProof.proof) and is therefore attacker-controlled at the network boundary until validated. A malicious peer could trigger a crash by returning a crafted inclusion proof with a length mismatch.

Patches

The patch for this vulnerability is included as part of v1.3.0.

Workarounds

No known workarounds know.

Пакеты

Наименование

nimiq-transaction

rust
Затронутые версииВерсия исправления

<= 0.2.0

Отсутствует

EPSS

Процентиль: 25%
0.00318
Низкий

3.1 Low

CVSS3

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 3.1
nvd
5 месяцев назад

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` panics on a malformed proof where `history.len() != positions.len()` due to `assert_eq!(history.len(), positions.len())`. The proof object is derived from untrusted p2p responses (`ResponseTransactionsProof.proof`) and is therefore attacker-controlled at the network boundary until validated. A malicious peer could trigger a crash by returning a crafted inclusion proof with a length mismatch. The patch for this vulnerability is included as part of v1.3.0. No known workarounds are available.

EPSS

Процентиль: 25%
0.00318
Низкий

3.1 Low

CVSS3

Дефекты

CWE-617