LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-33471

CVE-2026-33471 - Vulnerability Analysis

CriticalCVSS: 9.6

Last Updated: April 24, 2026

nimiq-block - Authentication Bypass

Published: April 22, 2026Updated: April 24, 2026Remote Exploitable

Overview

nimiq-block < 1.3.0 contains a signature verification bypass caused by out-of-range MultiSignature.signers indices colliding on u16 slots in SkipBlockProof::verify, letting malicious validators bypass quorum checks, exploit requires crafted SkipBlockProof.

Severity & Score

Severity: Critical
CVSS Score: 9.6
EPSS Score: 2.7%(Probability of exploitation in next 30 days)

Impact

Malicious validators can bypass quorum verification, allowing unauthorized block approval with fewer valid signatures.

Mitigation

Update to version 1.3.0 or later.

Social Media Activity(1 post)

OffSequence
OffSequence
@offseq
Apr 23, 2026

🔥 CRITICAL vuln in nimiq-block (<1.3.0): Flawed input validation in SkipBlockProof::verify lets attackers bypass PoS quorum using crafted indices. Patch in v1.3.0 — upgrade ASAP! CVE-2026-33471 https://radar.offseq.com/threat/cve-2026-33471-cwe-20-improper-input-validation-in-2bd8708b #OffSeq #Rust #Security #Blockchain

View original post

Details

CVE ID
CVE-2026-33471
Severity
Critical
CVSS Score
9.6
Type
broken_authentication
Status
confirmed
EPSS
2.7%
Social Posts
1

CWE

  • CWE-20

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

EPSS Score

2.7%Probability of exploitation in the next 30 days