Junglewise Threat Intelligence

CVE-2026-46540: Nimiq Albatross state synchronization failure in LightBlockchain rebranch

CVE-2026-46540 · Severity: medium · CVSS 6.5 · Published 2026-06-10

Technologies: Nimiq Albatross. Vendors: Nimiq.

Executive brief

A flaw in the Nimiq blockchain's light client software can cause it to stop processing new blocks correctly when switching between different versions of the transaction history. This occurs because the software fails to update its internal record of network validators and checkpoints during certain chain updates. If exploited or triggered by network conditions, this can lead to a permanent stall of the light client, preventing users from syncing with the network or verifying transactions.

Technical details

A vulnerability exists in the `LightBlockchain::rebranch()` function of the Nimiq Rust implementation. When the client adopts a fork chain ending in a macro block (checkpoint or election), it updates the chain head but fails to update critical state variables including `macro_head`, `election_head`, and `current_validators`. This inconsistent state causes subsequent macro blocks to fail `verify_macro_successor()` checks and subsequent regular blocks to fail `verify_validators()` if the rebranch target was an election block. The resulting validation failures effectively stall the light client's chain progression. The issue is resolved in version 1.4.0 by ensuring all macro/election states are correctly synchronized during a rebranch.

Affected products

  • Nimiq Nimiq Albatross (core-rs-albatross) < 1.4.0

Timeline

  • 2026-04-22: patched: Version 1.4.0 released
  • 2026-05-15: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE published to NVD

References

Related threats