Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3763-qp59-59vf

Опубликовано: 12 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

nimiq-blockchain: Validity store off by one error

Impact

The validity store treats a transaction with stored block_number = X as "in window" only when X > last_bn - transaction_validity_window_blocks (strict inequality). However the protocol's Transaction::is_valid_at accepts a transaction for inclusion in any block in [validity_start_height - blocks_per_batch, validity_start_height + window - 1]. By choosing validity_start_height = X + blocks_per_batch (the largest value still compatible with first inclusion at block X), an attacker can replay the same signed transaction in any block B such that X + window < B < validity_start_height + window, i.e., a contiguous window of blocks_per_batch - 1 blocks (59 on MainNet, ~10 minutes) during which the replay-protection check fails to flag it. The same transaction is then executed twice: the sender is debited twice, the recipient credited twice.

Patches

https://github.com/nimiq/core-rs-albatross/pull/3772

Workarounds

No known workarounds

Пакеты

Наименование

nimiq-blockchain

rust
Затронутые версииВерсия исправления

<= 1.5.0

1.5.1

EPSS

Процентиль: 33%
0.00392
Низкий

7.5 High

CVSS3

Дефекты

CWE-193
CWE-294

Связанные уязвимости

CVSS3: 7.5
nvd
26 дней назад

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transaction::is_valid_at, allowing a remote attacker to replay the same signed transaction during a blocks_per_batch minus one block window and cause the sender and recipient balances to be updated twice. This issue is fixed in version 1.5.1.

EPSS

Процентиль: 33%
0.00392
Низкий

7.5 High

CVSS3

Дефекты

CWE-193
CWE-294