CVE-2026-34062: Nimiq Proof-Of-Stake
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer can send only a partial frame and keep the substream open. because `Behaviour::new` also sets `with_max_concurrent_streams(1000)`, the node exposes a much larger stalled-slot budget than the library default. The patch for this vulnerability is formally released as part of v1.3.0. No known workarounds are available.
Affected products
- Nimiq Nimiq Proof-Of-Stake: before 1.3.0 (fixed in 1.3.0)
Published 2026-04-22. Last modified 2026-06-17.