<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:36:30 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-319837</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319837</link>
      <description>EUVD-2026-319837</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319837</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40092</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40092</link>
      <description>&lt;p&gt;nimiq-blockchain provides persistent block storage for Nimiq&amp;#39;s Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned&amp;lt;ValidatorRecord, KeyPair&amp;gt; with a signature field whose byte length is not exactly 64 in order to cause a crash. When the victim node&amp;#39;s DHT verifier calls TaggedSigned::verify, execution reaches Ed25519Signature::from_bytes(sig).unwrap() in the TaggedPublicKey implementation for Ed25519PublicKey. The from_bytes call fails because ed25519_zebra::Signature::try_from rejects slices not 64 bytes, and the unwrap() panics. The BLS TaggedPublicKey implementation correctly returns false on error; only the Ed25519 implementation panics. This issue has been fixed in version 1.4.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nimiq-blockchain provides persistent block storage for Nimiq&amp;#39;s Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned&amp;lt;ValidatorRecord, KeyPair&amp;gt; with a signature field whose byte length is not exactly 64 in order to cause a crash. When the victim node&amp;#39;s DHT verifier calls TaggedSigned::verify, execution reaches Ed25519Signature::from_bytes(sig).unwrap() in the TaggedPublicKey implementation for Ed25519PublicKey. The from_bytes call fails because ed25519_zebra::Signature::try_from rejects slices not 64 bytes, and the unwrap() panics. The BLS TaggedPublicKey implementation correctly returns false on error; only the Ed25519 implementation panics. This issue has been fixed in version 1.4.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40092</guid>
    </item>
    <item>
      <title>GHSA-27w2-87xv-37c6 — nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-27w2-87xv-37c6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: nimiq-keys&lt;/p&gt;
&lt;p&gt;### Impact
A malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record containing a `TaggedSigned&amp;lt;ValidatorRecord, KeyPair&amp;gt;` with a signature field whose byte length is not exactly 64. When the victim node&amp;#39;s DHT verifier calls `TaggedSigned::verify`, execution reaches `Ed25519Signature::from_bytes(sig).unwrap()` in the `TaggedPublicKey` implementation for `Ed25519PublicKey`. The `from_bytes` call fails because `ed25519_zebra::Signature::try_from` rejects slices not 64 bytes, and the `unwrap()` panics. The BLS `TaggedPublicKey` implementation correctly returns `false` on error; only the Ed25519 implementation panics.&lt;/p&gt;
&lt;p&gt;### Patches
[The patch for this vulnerability](https://github.com/nimiq/core-rs-albatross/pull/3708) is formally released as part of [v1.4.0](https://github.com/nimiq/core-rs-albatross/releases/tag/v1.4.0).&lt;/p&gt;
&lt;p&gt;### Workarounds
No known workarounds.&lt;/p&gt;
&lt;p&gt;### Resources
See [PR](https://github.com/nimiq/core-rs-albatross/pull/3708).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: nimiq-keys&lt;/p&gt;
&lt;p&gt;### Impact
A malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record containing a `TaggedSigned&amp;lt;ValidatorRecord, KeyPair&amp;gt;` with a signature field whose byte length is not exactly 64. When the victim node&amp;#39;s DHT verifier calls `TaggedSigned::verify`, execution reaches `Ed25519Signature::from_bytes(sig).unwrap()` in the `TaggedPublicKey` implementation for `Ed25519PublicKey`. The `from_bytes` call fails because `ed25519_zebra::Signature::try_from` rejects slices not 64 bytes, and the `unwrap()` panics. The BLS `TaggedPublicKey` implementation correctly returns `false` on error; only the Ed25519 implementation panics.&lt;/p&gt;
&lt;p&gt;### Patches
[The patch for this vulnerability](https://github.com/nimiq/core-rs-albatross/pull/3708) is formally released as part of [v1.4.0](https://github.com/nimiq/core-rs-albatross/releases/tag/v1.4.0).&lt;/p&gt;
&lt;p&gt;### Workarounds
No known workarounds.&lt;/p&gt;
&lt;p&gt;### Resources
See [PR](https://github.com/nimiq/core-rs-albatross/pull/3708).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-27w2-87xv-37c6</guid>
    </item>
  </channel>
</rss>
