CVE-2023-34458: Multiversx Mx-Chain-Go

Medium severity, CVSS 5.3. EPSS: 1.3% chance of exploitation in the next 30 days.

mx-chain-go is the official implementation of the MultiversX blockchain protocol, written in golang. When executing a relayed transaction, if the inner transaction failed, it would have increased the inner transaction's sender account nonce. This could have contributed to a limited DoS attack on a targeted account. The fix is a breaking change so a new flag `RelayedNonceFixEnableEpoch` was needed. This was a strict processing issue while validating blocks on a chain. This vulnerability has been patched in version 1.4.17.

Affected products

  • Multiversx Mx-Chain-Go: before 1.4.17 (fixed in 1.4.17)

Published 2023-07-13. Last modified 2026-06-17.