# CVE-2026-44505

## Summary

- **CVE ID:** CVE-2026-44505
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
- **CWE:** CWE-755
- **Published:** Jun 9, 2026
- **Last Modified:** Jun 10, 2026

## Description

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/src/swarm.rs). Prior to version 1.4.0, when a peer returns a FoundRecord, the code verifies the record via dht_verifier.verify(&record.record). On verifier error, handle_dht_get logs and returns early without completing the oneshot used by Network::dht_get, and without cleaning up per-query bookkeeping. Later query progress can hit the "DHT inconsistent state" path and also return without cleanup. Because Network::dht_get awaits the oneshot without a timeout, the caller future can hang indefinitely. This issue has been patched in version 1.4.0.

## Affected Products

- nimiq — core-rs-albatross (< 1.4.0)

## References

- [CNA](https://github.com/nimiq/core-rs-albatross/security/advisories/GHSA-g39c-jcgg-qwvr)
- [CNA](https://github.com/nimiq/core-rs-albatross/pull/3716)
- [CNA](https://github.com/nimiq/core-rs-albatross/releases/tag/v1.4.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._