PT-2026-30254 · Nimiq · Core-Rs-Albatross

·

CVE-2026-34061

·

Published

2026-04-03

·

Updated

2026-07-24

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions nimiq/core-rs-albatross versions prior to 1.3.0
Description An elected validator proposer can send an election macro block where the header.interlink does not match the canonical next interlink. This occurs because the verify macro block proposal() function validates the header shape, successor relation, proposer, body root, and state, but fails to check the interlink binding for election blocks. Consequently, validators prevote and precommit the malformed header hash, and the block is only rejected by verify block() during the push phase with an InvalidInterlink error after Tendermint has already decided the block.
Recommendations Update to version 1.3.0.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34061
GHSA-GR83-J5F8-P2R5

Affected Products

Core-Rs-Albatross