| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-h9cc-w26m-j342 | nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nimiq
Nimiq core-rs-albatross |
|
| Vendors & Products |
Nimiq
Nimiq core-rs-albatross |
Wed, 10 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. Ed25519PublicKey::delinearize() in keys/src/multisig/mod.rs called .unwrap() on curve point decompression, which panics when a public key is constructed from 32 bytes that do not represent a valid point on the Ed25519 curve. Ed25519PublicKey construction only validates byte length, not curve membership, so invalid keys can reach the delinearization path and crash the hosting process. This issue has been patched in version 1.4.0. | |
| Title | nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-10T13:11:58.177Z
Reserved: 2026-05-14T20:42:31.368Z
Link: CVE-2026-46542
Updated: 2026-06-10T13:11:54.603Z
Status : Received
Published: 2026-06-10T00:16:54.500
Modified: 2026-06-10T00:16:54.500
Link: CVE-2026-46542
No data.
OpenCVE Enrichment
Updated: 2026-06-10T02:15:19Z
Github GHSA