CVE-2026-33184

Nimiq · core-rs-albatross

The core-rs-albatross Rust implementation of the Nimiq Proof-of-Stake protocol contains a high-severity vulnerability affecting its consensus mechanism.

Executive summary

A high-severity vulnerability in the Nimiq core-rs-albatross implementation could compromise the consensus and stability of the Nimiq blockchain protocol.

Vulnerability

This vulnerability affects the Rust implementation of the Albatross consensus algorithm. An attacker could potentially exploit this flaw to disrupt the Proof-of-Stake protocol, leading to network instability or improper validation of blockchain transactions.

Business impact

For organizations and users participating in the Nimiq network, this vulnerability poses a risk to the integrity of the blockchain and the availability of the network. The CVSS score of 7.5 highlights the potential for significant disruption to financial operations and the overall trust in the protocol's security.

Remediation

Immediate Action: Update the core-rs-albatross node software to the latest secure version provided by the Nimiq development team.

Proactive Monitoring: Monitor node health and consensus participation metrics for anomalies that could indicate an attempted exploit of the protocol.

Compensating Controls: Ensure that blockchain nodes are running in a secure environment with restricted network access to prevent direct exposure to malicious actors.

Exploitation status

Public Exploit Available: false

Analyst recommendation

All Nimiq network participants using the Rust implementation should update their nodes immediately. Maintaining the integrity of the consensus algorithm is paramount to the security of the entire blockchain ecosystem.