Unchecked Return Value Affecting nimiq-keys package, versions <1.4.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-NIMIQKEYS-16874151
  • published25 May 2026
  • disclosed15 May 2026
  • creditPiravlos

Introduced: 15 May 2026

NewCVE-2026-40092  (opens in a new tab)
CWE-252  (opens in a new tab)

How to fix?

Upgrade nimiq-keys to version 1.4.0 or higher.

Overview

Affected versions of this package are vulnerable to Unchecked Return Value via the TaggedPublicKey::verify process. An attacker can cause a remote node to panic by submitting a crafted Kademlia DHT record containing a TaggedSigned<ValidatorRecord, KeyPair> with a signature field whose byte length is not exactly 64.

CVSS Base Scores

version 4.0
version 3.1