CVE-2026-46542

MEDIUM

nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points

Title source: cna
STIX 2.1

Description

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability exists in the Ed25519 multisig delinearization code path. Ed25519PublicKey::delinearize() in keys/src/multisig/mod.rs called .unwrap() on curve point decompression, which panics when a public key is constructed from 32 bytes that do not represent a valid point on the Ed25519 curve. Ed25519PublicKey construction only validates byte length, not curve membership, so invalid keys can reach the delinearization path and crash the hosting process. This issue has been patched in version 1.4.0.

References (3)

Core 3

Scores

CVSS v3 4.3
EPSS 0.0023
EPSS Percentile 13.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (2)
crates.io/nimiq-keys 0 - 1.4.0crates.io
nimiq/core-rs-albatross < 1.4.0
Published Jun 10, 2026
Tracked Since Jun 10, 2026