Discovery peer contact book poisoning via future timestamps
Fixed in: v1.3.0
details
- Finding IDs
- F-NIMIQ-DISCOVERY-TIMESTAMP-POISON-001
- GHSA
- GHSA-hj3g-hh5f-63mp
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
- Upstream title
- Discovery peer contact book poisoning via future timestamps
- Upstream CWE
- CWE-345, CWE-1284
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: finder (accepted)
F-NIMIQ-DISCOVERY-TIMESTAMP-POISON-001: Input / state handling. Discovery timestamps lack the required future-time range check. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-NIMIQ-DISCOVERY-TIMESTAMP-POISON-001
Security area (1seal assessment): Integrity. Unchecked future timestamps can poison the peer contact book, compromising the integrity of stored discovery state. Reviewed 24 Sep 2026.