CVE-2026-46540

Source
https://cve.org/CVERecord?id=CVE-2026-46540
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46540.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-46540
Aliases
  • GHSA-m3pg-qc2q-mg8c
Published
2026-06-09T23:45:01.847Z
Modified
2026-07-15T01:49:18.211497248Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
Summary
Nimiq light-blockchain: Light blockchain rebranch issue
Details

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a fork chain whose tip is a macro block (checkpoint or election), it only updates self.head but fails to update self.macrohead, self.electionhead, self.currentvalidators, or store the election header in the chainstore. This is in direct contrast with the full Blockchain::rebranch() at blockchain/src/blockchain/push.rs:504-518, which correctly updates all macro/election state when the new head is a macro block. After a rebranch to a macro block, the stale macrohead causes subsequent macro blocks pushed via push() to be verified against the wrong predecessor via verifymacrosuccessor(&this.macrohead). If the rebranch target was an election block, the stale currentvalidators causes every subsequent block to fail verifyvalidators(), completely stalling the light client's chain progression. This issue has been patched in version 1.4.0.

Database specific
{
    "cwe_ids": [
        "CWE-841"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46540.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nimiq/core-rs-albatross

Affected ranges

Type
GIT
Repo
https://github.com/nimiq/core-rs-albatross
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.4.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.0-rc.0
v0.1.0-rc.1
v0.1.0-rc.2
v0.1.0-rc.3
v0.10.0
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.12.0
v0.12.1
v0.13.0
v0.13.1
v0.14.0
v0.15.0
v0.16.0
v0.16.1
v0.17.0
v0.18.0
v0.19.0
v0.2.0
v0.2.1
v0.2.2
v0.20.0
v0.20.1
v0.20.2
v0.20.3
v0.20.4
v0.20.5
v0.21.0
v0.21.1
v0.22.0
v0.22.1
v0.22.2
v0.22.3
v0.23.0
v0.24.0
v0.24.1
v0.24.2
v0.24.3
v0.24.4
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.4.0
v0.4.1
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.6.0
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.9.0
v1.*
v1.0.0
v1.0.0-rc.0
v1.0.0-rc.1
v1.0.0-rc.2
v1.0.0-rc.3
v1.0.0-rc.4
v1.0.0-rc.5
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v1.2.2
v1.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46540.json"