`UpdateValidator` transactions allows voting key change without proof-of-knowledge
Fixed in: v1.3.0
details
- Finding IDs
- F-NIMIQ-ROGUEKEY-001
- CVE
- CVE-2026-34068
- GHSA
- GHSA-pf4j-pf3w-95f9
- Status
- patched
- Fixed in
- v1.3.0
- Recorded credit
- finder: @1seal
- Note
- GHSA-pf4j-pf3w-95f9; patched in v1.3.0 via PR #3654
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- `UpdateValidator` transactions allows voting key change without proof-of-knowledge
- Upstream CWE
- CWE-347
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: finder (accepted)
F-NIMIQ-ROGUEKEY-001: Verification failures. New voting keys are accepted without proof of knowledge. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-NIMIQ-ROGUEKEY-001
Security area (1seal assessment): Integrity. A voting key is accepted without proof of knowledge, undermining the integrity of aggregate-signature verification. Reviewed 24 Sep 2026.