HistoryStore::put_historic_txns uses an assert! to enforce invariants about HistoricTransaction.block_number (must be within the macro block being pushed and within the same epoch). During history sync, a peer can influence the history: &[HistoricTransaction] input passed into Blockchain::push_history_sync, and a malformed history list can violate these invariants and trigger a panic.
extend_history_sync calls this.history_store.add_to_history(..) before comparing the computed history root against the macro block header (block.history_root()), so the panic can happen before later rejection checks run.
The patch for this vulnerability is included as part of v1.3.0.
No known workarounds.
{
"cwe_ids": [
"CWE-20",
"CWE-617",
"CWE-754"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-22T19:23:55Z",
"nvd_published_at": "2026-04-22T20:16:41Z",
"severity": "MODERATE"
}