CVE-2025-47270
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. The `nimiq-network-libp2p` subcrate of nimiq/core-rs-albatross is vulnerable to a Denial of Service (DoS) attack due to uncontrolled memory allocation. Specifically, the implementation of the `Discovery` network message handling allocates a buffer based on a length value provided by the peer, without enforcing an upper bound. Since this length is a `u32`, a peer can trigger allocations of up to 4 GB, potentially leading to memory exhaustion and node crashes.
Leer descripción completaMostrar menos
As Discovery messages are regularly exchanged for peer discovery, this vulnerability can be exploited repeatedly. The patch for this vulnerability is formally released as part of v1.1.0. The patch implements a limit to the discovery message size of 1 MB and also resizes the message buffer size incrementally as the data is read. No known workarounds are available.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.71%
- Percentil entre todas las CVEs puntuadas: 52
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 %
Red sin privilegios (AV:N, PR:N). Asignación de buffer sin límite superior (u32 hasta 4 GB) en manejo de mensajes Discovery causa agotamiento de memoria y crashes repetibles.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-400
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-47270",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-47270",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-12T12:13:56.749363Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "nimiq",
"product": "core-rs-albatross",
"versions": [
{
"status": "affected",
"version": "< 1.1.0"
}
]
}
]
}
],
"published": "2025-05-12T11:15:51.050",
"references": [
{
"url": "https://github.com/nimiq/core-rs-albatross/commit/566935f0dd0fb41bba1f406d8e3a02dc499520b5",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nimiq/core-rs-albatross/pull/3384",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nimiq/core-rs-albatross/releases/tag/v1.1.0",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/nimiq/core-rs-albatross/security/advisories/GHSA-3v6r-9cr8-q433",
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. The `nimiq-network-libp2p` subcrate of nimiq/core-rs-albatross is vulnerable to a Denial of Service (DoS) attack due to uncontrolled memory allocation. Specifically, the implementation of the `Discovery` network message handling allocates a buffer based on a length value provided by the peer, without enforcing an upper bound. Since this length is a `u32`, a peer can trigger allocations of up to 4 GB, potentially leading to memory exhaustion and node crashes. As Discovery messages are regularly exchanged for peer discovery, this vulnerability can be exploited repeatedly. The patch for this vulnerability is formally released as part of v1.1.0. The patch implements a limit to the discovery message size of 1 MB and also resizes the message buffer size incrementally as the data is read. No known workarounds are available."
},
{
"lang": "es",
"value": "nimiq/core-rs-albatross es una implementación en Rust del protocolo Nimiq Proof-of-Stake, basado en el algoritmo de consenso Albatross. La subcaja `nimiq-network-libp2p` de nimiq/core-rs-albatross es vulnerable a un ataque de denegación de servicio (DoS) debido a la asignación de memoria incontrolada. En concreto, la implementación del sistema de gestión de mensajes de red `Discovery` asigna un búfer según la longitud proporcionada por el par, sin imponer un límite superior. Dado que esta longitud es `u32`, un par puede activar asignaciones de hasta 4 GB, lo que podría provocar el agotamiento de la memoria y caídas del nodo. Dado que los mensajes de Discovery se intercambian regularmente para el descubrimiento de pares, esta vulnerabilidad puede explotarse repetidamente. El parche para esta vulnerabilidad se publicó oficialmente como parte de la versión 1.1.0. El parche implementa un límite de 1 MB para el tamaño de los mensajes de descubrimiento y también ajusta el tamaño del búfer de mensajes de forma incremental a medida que se leen los datos. No se conocen workarounds."
}
],
"lastModified": "2026-06-17T09:27:38.520",
"sourceIdentifier": "security-advisories@github.com"
}