{"count":427,"offset":0,"registry_version":"v0.2","techniques":[{"bound_failure":"absent-invariant","classification":"curated","display_name":"Addr Message Counter Overflow Crash","external_references":[{"id":"CVE-2024-52919","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52919"}],"family":"fault_termination","first_seen":"2024-01-01","id":"NRDAX-T0001","instances":[{"bundle_ref":"btc_addr_overflow_flood","chain":"litecoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2024-52919","kind":"cve","url":"https://bitcoincore.org/en/2025/04/28/disclose-cve-2024-52919/"}],"fidelity":"lab","primitive_id":"btc_addr_overflow_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-52919 (GHSA-qwp9-p9rr-h729): addr flood → CAddrMan 32-bit nIdCount overflow → assertion abort","name":"addr-message-counter-overflow-crash","producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'addr-message-counter-overflow-crash'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Alert Message Ordering Bypass","external_references":[{"id":"CVE-2016-10725","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10725"}],"family":null,"first_seen":"2016-01-01","id":"NRDAX-T0002","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Alert Message Ordering Bypass","name":"alert-message-ordering-bypass","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'alert-message-ordering-bypass')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012","name":"Exploit Smart Contract Implementation","url":"https://aadapt.mitre.org/techniques/ADT3012"},"display_name":"Arithmetic Bug Fund Miscalculation","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0003","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Arithmetic Bug Fund Miscalculation","name":"arithmetic-bug-fund-miscalculation","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'arithmetic-bug-fund-miscalculation')","status":"active"},{"classification":"pending","display_name":"Arithmetic Edge-Case Panic Crash","external_references":[{"id":"GHPR-Conflux-Chain-conflux-rust-3544","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0004","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Arithmetic Edge-Case Panic Crash","name":"arithmetic-panic-crash","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'arithmetic-panic-crash')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Array Deserialization Memcpy Corruption","external_references":[],"family":"fault_termination","first_seen":"2019-01-01","id":"NRDAX-T0005","instances":[{"bundle_ref":"monero_levin_array_memcorrupt","chain":"monero","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0637","kind":"vendor-advisory","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0637"}],"fidelity":"lab","primitive_id":"monero_levin_array_memcorrupt"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2018-3972 (TALOS-2018-0637): Levin array-of-arrays (0x8D) → epee read_ae POD memcpy → memory corruption","name":"array-deserialization-memcpy-corruption","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'array-deserialization-memcpy-corruption'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Async Runtime Blocking VM Execution","external_references":[],"family":"compute_amp","first_seen":"2026-07-09","id":"NRDAX-T0006","instances":[{"bundle_ref":"eth_call_stateoverride_gascap_interpreter_compute_burn","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_call_stateoverride_gascap_interpreter_compute_burn"},{"bundle_ref":"iota_f14_devinspect_cpu_wedge","chain":"iota","discovery_origin":"original-research","external_references":[{"id":"https://docs.iota.org/references/iota-api/iota/method/iota_devInspectTransactionBlock","kind":"vendor-advisory","url":"https://docs.iota.org/references/iota-api/iota/method/iota_devInspectTransactionBlock (iota-core authority.rs dev_inspect_transaction_block synchronous Move-VM path; iota-json-rpc-api/src/write.rs exposes iota_devInspectTransactionBlock)"}],"fidelity":"lab","primitive_id":"iota_f14_devinspect_cpu_wedge"},{"bundle_ref":"iota_f14_f10_grpc_chained","chain":"iota","discovery_origin":"original-research","external_references":[{"id":"https://docs.iota.org/references/iota-api/iota/method/iota_devInspectTransactionBlock","kind":"vendor-advisory","url":"https://docs.iota.org/references/iota-api/iota/method/iota_devInspectTransactionBlock (F14: iota-core authority.rs synchronous dev_inspect Move-VM path) + https://docs.iota.org/references/iota-api (F10: gRPC LedgerService/GetTransactions batch response-amp, no per-batch count cap / no digest dedup)"}],"fidelity":"lab","primitive_id":"iota_f14_f10_grpc_chained"},{"bundle_ref":"SOL_F14_simulate_transaction_sync_wedge","chain":"solana","discovery_origin":"original-research","external_references":[{"id":"agave-simulatetransaction-rpc-executor-saturation","kind":"nr-brief","title":"How unauthenticated simulateTransaction requests saturate an Agave RPC node's executor pool","url":"https://nullrabbit.ai/research/agave-simulatetransaction-rpc-executor-saturation"}],"fidelity":"lab","primitive_id":"SOL_F14_simulate_transaction_sync_wedge"},{"bundle_ref":"sui_F14_devinspect_tokio_wedge","chain":"sui","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"sui_F14_devinspect_tokio_wedge"}],"lineage":{"deployments":4,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":5,"upper_bound":5},"mechanism":"The simulateTransaction RPC handler executes the BPF VM synchronously on the calling Tokio worker thread (no spawn_blocking interposed), and because sigVerify defaults off and simulation is gas-free, an attacker can submit CU-maximizing transactions against pre-loaded programs at no cost. Each concurrent request pins a shared executor thread for the full simulation duration, so per-worker throughput degrades proportionally to concurrent request count, exhausting the bounded async worker pool and starving all other RPC handlers sharing it. The fix-class is interposing async offload (spawn_blocking / dedicated thread pool with backpressure) plus request-side CU/cost accounting for simulate calls, not just on-chain compute budgets.","name":"async-runtime-blocking-vm-execution","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'async-runtime-blocking-vm-execution'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Authentication Message Replay","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0007","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Authentication Message Replay","name":"authentication-message-replay","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'authentication-message-replay')","status":"active"},{"classification":"pending","display_name":"Authorization Check Bypass RCE","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0008","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Authorization Check Bypass RCE","name":"authorization-check-bypass-rce","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'authorization-check-bypass-rce')","status":"active"},{"classification":"pending","display_name":"Bit-Length Validation Panic","external_references":[],"family":null,"first_seen":"2026-07-17","id":"NRDAX-T0009","instances":[{"bundle_ref":"nimiq_dht_sig_length_panic","chain":"nimiq","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"nimiq_dht_sig_length_panic"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2026-40092 / GHSA-27w2-87xv-37c6 (nimiq/core-rs-albatross, nimiq/core-rs-albatross before v1.4.0): validator records are published into the libp2p Kademlia DHT (/nimiq/kad/0.0.1) as TaggedSigned<ValidatorRecord> (tag 0x03). With set_record_filtering(FilterBoth) every inbound PUT_VALUE reaches Verifier::verify_validator_record, which calls validator_record.verify() -> TaggedPublicKey::verify for Ed25519, previously `Ed25519Signature::from_bytes(sig).unwrap()`. ed25519_zebra rejects any non-64-byte slice, so a record whose TaggedSignature byte-vector is not 64 bytes panics via unwrap() → remote unauthenticated crash DoS. Fixed in v1.4.0 (PR #3708, commit 807ee8e) (return false instead of unwrap). https://github.com/advisories/GHSA-27w2-87xv-37c6","name":"bit-length-validation-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'bit-length-validation-panic'","status":"active"},{"classification":"pending","display_name":"Block Processing Use-After-Free Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0010","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Block Processing Use-After-Free Crash","name":"block-processing-use-after-free-crash","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'block-processing-use-after-free-crash')","status":"active"},{"classification":"pending","display_name":"Block Replay Race Crash","external_references":[{"id":"GHPR-anza-xyz-agave-14199","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0011","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Block Replay Race Crash","name":"block-replay-race-crash","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'block-replay-race-crash')","status":"active"},{"classification":"pending","display_name":"Block Timestamp Validation Bypass","external_references":[{"id":"CVE-2022-37450","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37450"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0012","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Block Timestamp Validation Bypass","name":"block-timestamp-validation-bypass","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'block-timestamp-validation-bypass')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Bloom Filter Divide-By-Zero Crash","external_references":[],"family":"fault_termination","first_seen":"2026-07-01","id":"NRDAX-T0013","instances":[{"bundle_ref":"btc_bloom_divzero","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2013-5700","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5700"}],"fidelity":"lab","primitive_id":"btc_bloom_divzero"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2013-5700: empty BIP37 bloom filter → modulo-by-zero in CBloomFilter::Hash() → crash","name":"bloom-filter-divide-by-zero-crash","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'bloom-filter-divide-by-zero-crash'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Certificate Revocation Bypass","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0014","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Certificate Revocation Bypass","name":"certificate-revocation-bypass","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'certificate-revocation-bypass')","status":"active"},{"classification":"pending","display_name":"Chain ID Validation Missing","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0015","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Chain ID Validation Missing","name":"chain-id-validation-missing","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'chain-id-validation-missing')","status":"active"},{"classification":"pending","display_name":"ChainSync Jumping Protocol DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0016","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"ChainSync Jumping Protocol DoS","name":"chainsync-jumping-protocol-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'chainsync-jumping-protocol-dos')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012","name":"Exploit Smart Contract Implementation","url":"https://aadapt.mitre.org/techniques/ADT3012"},"display_name":"Channel Access Control Bypass","external_references":[],"family":null,"first_seen":"2019-01-01","id":"NRDAX-T0017","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Channel Access Control Bypass","name":"channel-access-control-bypass","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'channel-access-control-bypass')","status":"active"},{"classification":"pending","display_name":"Channel Close State Race Stranding","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0018","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Channel Close State Race Stranding","name":"channel-close-state-race-stranding","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'channel-close-state-race-stranding')","status":"active"},{"classification":"pending","display_name":"Channel Open Error Bypass","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0019","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Channel Open Error Bypass","name":"channel-open-error-bypass","out_of_scope":true,"producer_family":"bridge","provenance_note":"known-but-not-reproduced coverage gap (technique 'channel-open-error-bypass')","status":"active"},{"classification":"pending","display_name":"Checkpoint Snapshot Signer Bypass","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0020","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Checkpoint Snapshot Signer Bypass","name":"checkpoint-snapshot-signer-bypass","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'checkpoint-snapshot-signer-bypass')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012","name":"Exploit Smart Contract Implementation","url":"https://aadapt.mitre.org/techniques/ADT3012"},"display_name":"Claim Migration Fund Drain","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0021","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Claim Migration Fund Drain","name":"claim-migration-fund-drain","out_of_scope":true,"producer_family":"bridge","provenance_note":"known-but-not-reproduced coverage gap (technique 'claim-migration-fund-drain')","status":"active"},{"classification":"pending","display_name":"Client Library Supply Chain Compromise","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0022","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Client Library Supply Chain Compromise","name":"client-library-supply-chain-compromise","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'client-library-supply-chain-compromise')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Coalesced Packet Buffer Leak","external_references":[],"family":"memory_amp","first_seen":"2026-07-11","id":"NRDAX-T0023","instances":[{"bundle_ref":"lsquic_initial_prehandshake_leak","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-54939","kind":"cve","url":"https://www.imperva.com/blog/quic-leak-cve-2025-54939-new-high-risk-pre-handshake-remote-denial-of-service-in-lsquic-quic-implementation/"}],"fidelity":"lab","primitive_id":"lsquic_initial_prehandshake_leak"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"QUIC-LEAK / CVE-2025-54939: LSQUIC pre-handshake `packet_in` memory leak from coalesced Initial packets (CVSS 7.5 AV:N/AC:L/PR:N/UI:N/A:H, CWE-401+CWE-770; affected LSQUIC < 4.3.1, fixed 4.3.1 / OpenLiteSpeed 1.8.4 / LiteSpeed Web Server 6.3.4). An unauthenticated remote attacker floods UDP datagrams that each coalesce several QUIC v1 Initial packets — the first with a valid DCID, the rest with distinct invalid DCIDs; lsquic frees only the first coalesced packet_in per datagram and leaks (~96 B each) the rest, before any handshake, bypassing every post-handshake limit -> memory grows at ~70% of bandwidth -> OOM. PUBLIC-CVE REPLICATION captured here as the attack wire signature only (loopback UDP mock; no real lsquic endpoint stood up); the mock_leaked_* counters are a wire-side proxy for the pinned server memory.","name":"coalesced-packet-buffer-leak","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'coalesced-packet-buffer-leak'","status":"active","surface":"p2p-gossip"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Compact Block FillBlock Duplicate Crash","external_references":[],"family":"fault_termination","first_seen":"2026-07-07","id":"NRDAX-T0024","instances":[{"bundle_ref":"btc_blocktxn_double_fillblock","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/"}],"fidelity":"lab","primitive_id":"btc_blocktxn_double_fillblock"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-35202: blocktxn with txns not committed to the block merkle root → FillBlock called twice → assertion + node exit (Bitcoin Core <25.0)","name":"compact-block-fillblock-duplicate-crash","producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'compact-block-fillblock-duplicate-crash'","status":"active","surface":"consensus-ingest"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"Compact Block Size Integer Overflow","external_references":[],"family":"memory_amp","first_seen":"2026-07-02","id":"NRDAX-T0025","instances":[{"bundle_ref":"btc_cmpctblock_overflow","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-46597","kind":"cve","url":"https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-46597/"}],"fidelity":"lab","primitive_id":"btc_cmpctblock_overflow"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2025-46597: cmpctblock declaring >1GB short-ids → 32-bit size-calc overflow","name":"compact-block-size-integer-overflow","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'compact-block-size-integer-overflow'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Compiler Execution Order Bug","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0026","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Compiler Execution Order Bug","name":"compiler-execution-order-bug","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'compiler-execution-order-bug')","status":"active"},{"classification":"pending","display_name":"Compressed Message Checksum Bypass","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0027","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Compressed Message Checksum Bypass","name":"compressed-message-checksum-bypass","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'compressed-message-checksum-bypass')","status":"active"},{"classification":"pending","display_name":"Compressed Message Decompression Crash","external_references":[{"id":"CVE-2025-64702","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64702"},{"id":"GHPR-ethereum-optimism-optimism-21753","kind":"vendor-advisory"}],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0028","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Compressed Message Decompression Crash","name":"compressed-message-decompression-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'compressed-message-decompression-crash')","status":"active"},{"classification":"pending","display_name":"Concurrent RPC Race Nil-Deref Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0029","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Concurrent RPC Race Nil-Deref Panic","name":"concurrent-rpc-race-nil-deref-panic","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'concurrent-rpc-race-nil-deref-panic')","status":"active"},{"classification":"pending","display_name":"Connection Failure Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0030","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Connection Failure Panic Crash","name":"connection-failure-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'connection-failure-panic-crash')","status":"active"},{"classification":"pending","display_name":"Consensus Deadlock Vote Race","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0031","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Consensus Deadlock Vote Race","name":"consensus-deadlock-vote-race","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'consensus-deadlock-vote-race')","status":"active"},{"classification":"pending","display_name":"Consensus Future Vote OOM","external_references":[{"id":"GHPR-starkware-libs-sequencer-14757","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0032","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Consensus Future Vote OOM","name":"consensus-future-vote-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'consensus-future-vote-oom')","status":"active"},{"classification":"pending","display_name":"Consensus Message Crash DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0033","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Consensus Message Crash DoS","name":"consensus-message-crash-dos","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'consensus-message-crash-dos')","status":"active"},{"classification":"pending","display_name":"Container Escape via Dependency","external_references":[],"family":null,"first_seen":"2019-01-01","id":"NRDAX-T0034","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Container Escape via Dependency","name":"container-escape-dependency","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'container-escape-dependency')","status":"active"},{"classification":"pending","display_name":"Contract Activation Compute Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0035","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Contract Activation Compute Exhaustion","name":"contract-activation-compute-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'contract-activation-compute-exhaustion')","status":"active"},{"classification":"pending","display_name":"Contract Execution Engine Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0036","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Contract Execution Engine Crash","name":"contract-execution-engine-crash","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'contract-execution-engine-crash')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012","name":"Exploit Smart Contract Implementation","url":"https://aadapt.mitre.org/techniques/ADT3012"},"display_name":"Contract Logic Validation Bypass","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0037","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Contract Logic Validation Bypass","name":"contract-logic-validation-bypass","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'contract-logic-validation-bypass')","status":"active"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"Count Underflow Header Serving Amplification","dual_with":"response_amp","external_references":[],"family":"memory_amp","first_seen":"2026-07-07","id":"NRDAX-T0038","instances":[{"bundle_ref":"geth_getblockheaders_count_zero","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-4xc9-8hmq-j652","kind":"ghsa","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-4xc9-8hmq-j652"},{"id":"geth-getblockheaders-amount-zero-underflow-cve-2024-32972","kind":"nr-brief","title":"How a zero-value GetBlockHeaders request underflows to serve go-ethereum's entire header chain (CVE-2024-32972)","url":"https://nullrabbit.ai/research/geth-getblockheaders-amount-zero-underflow-cve-2024-32972"}],"fidelity":"lab","primitive_id":"geth_getblockheaders_count_zero"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-32972: eth GetBlockHeaders amount=0 → count-1 underflows to UINT64_MAX → bypasses maxHeadersServe → serves all headers to genesis → memory exhaustion (geth <1.13.15)","name":"count-underflow-header-serving-amplification","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'count-underflow-header-serving-amplification'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Crafted Packet Node Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0039","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Crafted Packet Node Crash","name":"crafted-packet-node-crash","out_of_scope":true,"producer_family":"bridge","provenance_note":"known-but-not-reproduced coverage gap (technique 'crafted-packet-node-crash')","status":"active"},{"classification":"pending","display_name":"Crafted Transaction Processing DoS","external_references":[{"id":"CVE-2025-46598","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46598"},{"id":"GHSA-4j93-fm92-rp4m","kind":"ghsa","url":"https://github.com/advisories/GHSA-4j93-fm92-rp4m"},{"id":"GHPR-ethereum-optimism-optimism-21609","kind":"vendor-advisory"},{"id":"GHPR-starkware-libs-sequencer-14841","kind":"vendor-advisory"}],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0040","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Crafted Transaction Processing DoS","name":"crafted-tx-processing-dos","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'crafted-tx-processing-dos')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Cross-Chain Peer Pool Pollution","external_references":[{"id":"SLOWMIST-ALIEN-ATTACK","kind":"vendor-advisory"}],"family":"connection_exhaustion","first_seen":"2026-07-08","id":"NRDAX-T0041","instances":[{"bundle_ref":"geth_alien_peer_pool_pollution","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md","kind":"vendor-advisory","url":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md"}],"fidelity":"lab","primitive_id":"geth_alien_peer_pool_pollution"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"Alien Attack (SlowMist 'peer-pool pollution'): a same-family but DIFFERENT-chain peer completes the chain-agnostic RLPx ECIES handshake + devp2p Hello and is admitted to the eth handshake; the chain check (networkID/genesis) happens only at eth Status, AFTER the full handshake — so an alien (Ethereum mainnet identity vs the target's privnet) forces geth to spend the whole ECIES+Hello handshake before disconnecting on the mismatch. Flooding alien handshakes wastes handshake CPU + occupies connection slots (peer-pool pollution). Class disclosed by SlowMist (first found the Alien Attack); no CVE.","name":"cross-chain-peer-pool-pollution","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'cross-chain-peer-pool-pollution'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Crypto Frame Reassembly Buffer Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-10","id":"NRDAX-T0042","instances":[{"bundle_ref":"quiche_crypto_frame_flood","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2024-1765","kind":"cve","url":"https://github.com/cloudflare/quiche/security/advisories/GHSA-78wx-jg4j-5j6g"}],"fidelity":"lab","primitive_id":"quiche_crypto_frame_flood"},{"bundle_ref":"s2n_quic_crypto_offset_amplification","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-10740","kind":"cve","url":"https://github.com/aws/s2n-quic/security/advisories/GHSA-9q54-f358-3fqf"}],"fidelity":"lab","primitive_id":"s2n_quic_crypto_offset_amplification"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"quiche QUIC CRYPTO-frame flood (CVE-2024-1765): flood of QUIC long-header packets each carrying a CRYPTO frame (type 0x06) whose offset escalates by a fixed stride (4096) — leaving the crypto reassembly stream permanently non-contiguous so the receiver retains every out-of-order range — and whose declared length (4096) exceeds the truncated (200-byte) body delivered, so a modest packet rate reserves an unbounded, monotonically-growing crypto-reassembly buffer. Real CVE is post-handshake 1-RTT CRYPTO frames; a loopback mock cannot complete a real TLS 1.3 handshake, so the reassembly-buffer-growth wire signature is modelled on the QUIC long-header CRYPTO surface (frame type + escalating offsets + oversized declared span are the load-bearing artefacts). public-cve-replication — replicated wire signature, not a NullRabbit measurement. Affected quiche <= 0.19.1, 0.20.0; fixed 0.19.2, 0.20.1; CVSS 3.1 5.9 (Moderate); reported by Marten Seemann. https://github.com/cloudflare/quiche/security/advisories/GHSA-78wx-jg4j-5j6g","name":"crypto-frame-reassembly-buffer-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'crypto-frame-reassembly-buffer-exhaustion'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Crypto Input Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0043","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Crypto Input Panic Crash","name":"crypto-input-panic-crash","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'crypto-input-panic-crash')","status":"active"},{"classification":"pending","display_name":"Data Limit Bypass State Bloat","external_references":[],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0044","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Data Limit Bypass State Bloat","name":"data-limit-bypass-state-bloat","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'data-limit-bypass-state-bloat')","status":"active"},{"classification":"pending","display_name":"Declare Transaction Compilation CPU Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0045","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Declare Transaction Compilation CPU Exhaustion","name":"declare-transaction-compilation-cpu-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'declare-transaction-compilation-cpu-exhaustion')","status":"active"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"Decompression Bomb Resource Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2019-01-01","id":"NRDAX-T0046","instances":[{"bundle_ref":"quic_go_qpack_decompression_bomb","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-64702","kind":"cve","url":"https://github.com/quic-go/quic-go/security/advisories/GHSA-g754-hx8w-x2g6"}],"fidelity":"lab","primitive_id":"quic_go_qpack_decompression_bomb"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"quic-go HTTP/3 QPACK decompression-bomb memory exhaustion (CVE-2025-64702): a flood of QUIC v1 short-header (1-RTT) packets, each carrying a STREAM frame (type 0x0b) on a fresh client bidi stream whose data is an HTTP/3 HEADERS frame (type 0x01) holding a QPACK block: field-section prefix 00 00 (static-only) + 128 Indexed Field Line refs to static index 85 ('content-security-policy: script-src 'none'; object-src 'none'; base-uri 'none'', 76 B) encoded as the 2 bytes 'ff 16' each. Each ref is 2 wire bytes but decodes to a 108-byte field-section entry, so a 258-byte block decodes to 13824 B (~54x, the advisory's ~50x). MODELLED AS A REPEATABLE FLOW: the CVE describes one crafted frame, but the learnable artefact is many such HEADERS frames across many fresh request streams driving SUSTAINED decoder allocation (pre-v0.57.0 there is no SETTINGS_MAX_FIELD_SECTION_SIZE cap, so the expanded field section is allocated per stream without bound). A loopback mock cannot complete a real TLS 1.3 handshake, so the load-bearing wire artefacts modelled are the HEADERS/QPACK frame structure, the static-index density, and the small-on-wire / large-decoded ratio across a stream flood (not real QUIC keys / 1-RTT crypto). public-cve-replication — replicated wire signature, not a NullRabbit measurement. Affected quic-go <= v0.56.0; fixed v0.57.0; severity Moderate (CVSS 5.3); reported by sfoxio (2025-12-11). https://github.com/quic-go/quic-go/security/advisories/GHSA-g754-hx8w-x2g6","name":"decompression-bomb-resource-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'decompression-bomb-resource-exhaustion'","status":"active","surface":"rpc-api"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT1552","name":"Unsecured Credentials","url":"https://aadapt.mitre.org/techniques/ADT1552"},"display_name":"Default Secret Token Forgery","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0047","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Default Secret Token Forgery","name":"default-secret-token-forgery","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'default-secret-token-forgery')","status":"active"},{"classification":"pending","display_name":"Dependency Use-After-Free Corruption","external_references":[{"id":"CVE-2026-11941","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11941"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0048","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Dependency Use-After-Free Corruption","name":"dependency-use-after-free-corruption","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'dependency-use-after-free-corruption')","status":"active"},{"classification":"pending","display_name":"DHT PUT_VALUE Disk Exhaustion","external_references":[{"id":"CVE-2026-45783","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45783"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0049","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"DHT PUT_VALUE Disk Exhaustion","name":"dht-put-value-disk-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'dht-put-value-disk-exhaustion')","status":"active"},{"classification":"pending","display_name":"DHT Sybil Content Censorship","external_references":[{"id":"CVE-2023-26248","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26248"}],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0050","instances":[{"bundle_ref":"ipfs_dht_sybil_censorship","chain":"ipfs","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-mqr9-hjr8-2m9w","kind":"ghsa","url":"https://github.com/advisories/GHSA-mqr9-hjr8-2m9w"}],"fidelity":"lab","primitive_id":"ipfs_dht_sybil_censorship"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2023-26248 / GHSA-mqr9-hjr8-2m9w: Content Censorship in IPFS via Kademlia DHT abuse. The libp2p Kademlia DHT (go-libp2p-kad-dht (Go; as shipped in go-ipfs/kubo), affected go-libp2p-kad-dht <= 0.20.0 / go-ipfs (kubo) <= 0.18.1) stores/serves a CID's provider record at the peers whose peer IDs have the smallest XOR distance to the CID, with no defence against an attacker manufacturing peer IDs in that neighbourhood. An attacker grinds many Sybil peer IDs closer to a target CID than any honest peer and joins them to the DHT, so the Sybils become the k-closest set for that CID: honest ADD_PROVIDER records land on the Sybils (dropped) and honest GET_PROVIDERS lookups converge on the Sybils, which return no honest provider (only more Sybil CLOSER_PEERS). A small number of strategically placed Sybils makes any content undiscoverable network-wide. Unauthenticated — any peer. Impact: content censorship (NDSS 2024 / arXiv:2307.12212). Protocol Labs deployed detection+mitigation in a later libp2p DHT release.","name":"dht-sybil-content-censorship","out_of_scope":true,"producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'dht-sybil-content-censorship'","status":"active"},{"classification":"pending","display_name":"Dial Worker Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0051","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Dial Worker Panic Crash","name":"dial-worker-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'dial-worker-panic-crash')","status":"active"},{"classification":"pending","display_name":"DNS Rebinding SSRF Bypass","external_references":[{"id":"GHSA-rjvw-7vvw-549v","kind":"ghsa","url":"https://github.com/advisories/GHSA-rjvw-7vvw-549v"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0052","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"DNS Rebinding SSRF Bypass","name":"dns-rebinding-ssrf-bypass","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'dns-rebinding-ssrf-bypass')","status":"active"},{"classification":"pending","display_name":"DNS Response Parsing Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0053","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"DNS Response Parsing Panic Crash","name":"dns-response-parsing-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'dns-response-parsing-panic-crash')","status":"active"},{"classification":"pending","display_name":"DNSSEC Validation Bypass Cache Poisoning","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0054","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"DNSSEC Validation Bypass Cache Poisoning","name":"dnssec-validation-bypass-cache-poisoning","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'dnssec-validation-bypass-cache-poisoning')","status":"active"},{"classification":"pending","display_name":"Duplicate-Input Block Crash","external_references":[{"id":"CVE-2018-17144","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17144"}],"family":null,"first_seen":"2018-01-01","id":"NRDAX-T0055","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Duplicate-Input Block Crash","name":"duplicate-input-block-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'duplicate-input-block-crash')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Duplicate Input Validation-Bypass Crash","external_references":[],"family":"fault_termination","first_seen":"2026-07-08","id":"NRDAX-T0056","instances":[{"bundle_ref":"bitcoin_dup_input_crash","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"bitcoin-core-duplicate-input-block-crash-cve-2018-17144","kind":"nr-brief","title":"How a missing duplicate-input check in Bitcoin Core let one block crash 0.14.x nodes and silently inflate the supply on 0.15.0-0.16.2 (CVE-2018-17144)","url":"https://nullrabbit.ai/research/bitcoin-core-duplicate-input-block-crash-cve-2018-17144"},{"id":"https://bitcoincore.org/en/2018/09/20/notice/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2018/09/20/notice/"}],"fidelity":"lab","primitive_id":"bitcoin_dup_input_crash"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2018-17144: a block whose tx spends one outpoint twice (duplicate inputs); the 0.14 pre-relay optimization (PR#9049) skipped the duplicate-input check → assert(!coin.IsNull()) crash (0.14.x) / supply inflation (0.15.0-0.16.2). Fixed 0.16.3/0.17.0. Patched node rejects bad-txns-inputs-duplicate.","name":"duplicate-input-validation-bypass-crash","producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'duplicate-input-validation-bypass-crash'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Duplicate Proof Memory Leak DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0057","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Duplicate Proof Memory Leak DoS","name":"duplicate-proof-memory-leak-dos","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'duplicate-proof-memory-leak-dos')","status":"active"},{"classification":"pending","display_name":"Duplicate Record Constraint Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0058","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Duplicate Record Constraint Crash","name":"duplicate-record-constraint-crash","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'duplicate-record-constraint-crash')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Duplicate Transport Parameter Memory Leak","external_references":[],"family":"memory_amp","first_seen":"2026-07-11","id":"NRDAX-T0059","instances":[{"bundle_ref":"msquic_dup_tp_versioninfo_leak","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2024-26190","kind":"cve","url":"https://github.com/microsoft/msquic/security/advisories/GHSA-2x7m-gf85-3745"}],"fidelity":"lab","primitive_id":"msquic_dup_tp_versioninfo_leak"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"msquic duplicate-transport-parameters VersionInfo leak (CVE-2024-26190): flood of QUIC v1 Initial packets (distinct SCID / new connection each), every Initial carrying a CRYPTO frame (type 0x06) whose body is a TLS ClientHello that repeats the quic_transport_parameters extension (0x0039) 32 times, each extension an encoded transport-parameters blob embedding a version_information TP (id 0x11). Pre-fix msquic re-decoded EACH duplicate into the same struct, allocating VersionInfo (QUIC_POOL_VERSION_INFO) per decode and zeroing without freeing -> one leaked heap buffer per duplicate; total leaked ~= connections x 32. The leak is driven during ClientHello extension parsing (pre-handshake-completion), so a loopback mock that cannot finish a real TLS 1.3 handshake still carries the load-bearing artefacts (duplicated 0x0039 extension + embedded 0x11 TP). public-cve-replication — replicated wire signature, not a NullRabbit measurement. Affected msquic < 2.1.12 (2.1.x), < 2.2.7 (2.2.x), < 2.3.5; fixed 2.1.12, 2.2.7, 2.3.5; CWE-401 (Missing Release of Memory) / CWE-400 (Uncontrolled Resource Consumption); CVSS 3.1 7.5 (High); fix commit d364feeda0dd8b729eca6fef149c1ef98630f0cb. https://github.com/microsoft/msquic/security/advisories/GHSA-2x7m-gf85-3745","name":"duplicate-transport-parameter-memory-leak","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'duplicate-transport-parameter-memory-leak'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Duplicate Transaction Memory Leak","external_references":[{"id":"CVE-2023-34451","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34451"}],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0060","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Duplicate Transaction Memory Leak","name":"duplicate-tx-memory-leak","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'duplicate-tx-memory-leak')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Duplicate Tx Mempool Index Desync","external_references":[],"family":"memory_amp","first_seen":"2026-07-09","id":"NRDAX-T0061","instances":[{"bundle_ref":"cometbft_mempool_dup_tx_leak","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-w24w-wp77-qffm","kind":"ghsa","url":"https://github.com/cometbft/cometbft/security/advisories/GHSA-w24w-wp77-qffm"}],"fidelity":"lab","primitive_id":"cometbft_mempool_dup_tx_leak"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2023-34451 (GHSA-w24w-wp77-qffm): the mempool's list + map index each other and can desync so the SAME tx appears multiple times in the list and can no longer be fully removed (only a restart clears it) — a MempoolChannel(0x30) Txs message carrying the same tx repeated drives the duplicate-insertion path; flooding identical txs is the wire signature (fixed v0.34.29 / v0.37.2).","name":"duplicate-tx-mempool-index-desync","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'duplicate-tx-mempool-index-desync'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Dust Output Consensus Mishandling","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0062","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Dust Output Consensus Mishandling","name":"dust-output-consensus-mishandling","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'dust-output-consensus-mishandling')","status":"active"},{"classification":"pending","display_name":"Dust Value Griefing","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0063","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Dust Value Griefing","name":"dust-value-griefing","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'dust-value-griefing')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Endpoint Concurrency Cap Exhaustion","external_references":[],"family":"connection_exhaustion","first_seen":"2026-07-04","id":"NRDAX-T0064","instances":[{"bundle_ref":"cosmos_grpc_stream_flood","chain":"cosmos","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"cosmos_grpc_stream_flood"},{"bundle_ref":"http2_settings_ack_stream_cap_bypass","chain":"http2","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"http2_settings_ack_stream_cap_bypass"},{"bundle_ref":"ic_xnet_concurrency_cap","chain":"ic","discovery_origin":"original-research","external_references":[{"id":"https://github.com/dfinity/ic","kind":"vendor-advisory","url":"https://github.com/dfinity/ic — rs/http_endpoints/xnet/src/lib.rs:54 (const XNET_ENDPOINT_MAX_CONCURRENT_REQUESTS: usize = 4), :156-168 (try_acquire_owned() NON-BLOCKING; overflow returns 503 body \"Queue full\" immediately, no queue), :214 (Semaphore::new(XNET_ENDPOINT_MAX_CONCURRENT_REQUESTS)), :261 (tls.server_config(SomeOrAllNodes::All) admits ANY registered IC node); compounds with rs/xnet/payload_builder/src/certified_slice_pool.rs:405 (byte_limit.unwrap_or(usize::MAX), no clamp on the byte_limit query param)."}],"fidelity":"lab","primitive_id":"ic_xnet_concurrency_cap"},{"bundle_ref":"iota_grpc_stream_cap_dos","chain":"iota","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"iota_grpc_stream_cap_dos"},{"bundle_ref":"kaspa_grpc_h2_preauth_stream_flood","chain":"kaspa","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"kaspa_grpc_h2_preauth_stream_flood"}],"lineage":{"deployments":5,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":5,"upper_bound":5},"mechanism":"cosmos-sdk server/grpc/server.go grpc.NewServer w/o grpc.MaxConcurrentStreams -> grpc-go default effectively unbounded + no SETTINGS_MAX_CONCURRENT_STREAMS signalled; attacker holds many HTTP/2 streams on one conn pinning per-stream state (~7KB) -> ~7GB single-source RSS pin (measured gaiad loopback). Sei fork sets MaxConcurrentStreams(100). COSMOS_SDK_GRPC_STREAM_FLOOD / C11.","name":"endpoint-concurrency-cap-exhaustion","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'endpoint-concurrency-cap-exhaustion'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Engine API Deadlock","external_references":[{"id":"GHPR-erigontech-erigon-22835","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0065","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Engine API Deadlock","name":"engine-api-deadlock","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'engine-api-deadlock')","status":"active"},{"classification":"pending","display_name":"Epoch Boundary Crash Loop","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0066","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Epoch Boundary Crash Loop","name":"epoch-boundary-crash-loop","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'epoch-boundary-crash-loop')","status":"active"},{"classification":"pending","display_name":"Epoch Height Source Lag Stall","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0067","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Epoch Height Source Lag Stall","name":"epoch-height-source-lag-stall","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'epoch-height-source-lag-stall')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3007","name":"Exploit Consensus Logic","url":"https://aadapt.mitre.org/techniques/ADT3007"},"display_name":"Equivocation Evidence Window Bypass","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0068","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Equivocation Evidence Window Bypass","name":"equivocation-evidence-window-bypass","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'equivocation-evidence-window-bypass')","status":"active"},{"classification":"pending","display_name":"Equivocation Storm Liveness DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0069","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Equivocation Storm Liveness DoS","name":"equivocation-storm-liveness-dos","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'equivocation-storm-liveness-dos')","status":"active"},{"classification":"pending","display_name":"Ethash Cache Generation Memory Exhaustion","external_references":[{"id":"CVE-2021-42219","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42219"}],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0070","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Ethash Cache Generation Memory Exhaustion","name":"ethash-cache-generation-memory-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'ethash-cache-generation-memory-exhaustion')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Ethash Verification Memory Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-09","id":"NRDAX-T0071","instances":[{"bundle_ref":"geth_ethash_memory_exhaustion_dos","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2021-42219","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-42219"}],"fidelity":"lab","primitive_id":"geth_ethash_memory_exhaustion_dos"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2021-42219: go-ethereum v1.10.9 (and earlier pre-Merge ethash-verifying geth) — an unauthenticated remote peer floods a node with an excessive amount of block/header messages; to verify each block's PoW geth must hold the ethash cache for that block's epoch (number // 30000; ~16 MB+ each, generated in consensus/ethash/algorithm.go), so a flood whose announced block numbers span many distinct epochs forces many large cache allocations -> memory exhaustion (the cache for the claimed epoch is generated BEFORE the invalid mixHash/nonce is rejected, so a bogus PoW still triggers the cost). Network-triggered, availability-only (CVSS 7.5, AV:N/A:H). No vendor GHSA; the ethash PoW path was removed at The Merge (Sept 2022), so this is a pre-Merge class. Faithful known-class replication of the flood wire signature; the OOM impact is the CVE's, not reproduced against a live node.","name":"ethash-verification-memory-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'ethash-verification-memory-exhaustion'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Event Stream Endpoint Crash DoS","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0072","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Event Stream Endpoint Crash DoS","name":"event-stream-endpoint-crash-dos","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'event-stream-endpoint-crash-dos')","status":"active"},{"classification":"pending","display_name":"Evidence Timestamp Inconsistency DoS","external_references":[{"id":"CVE-2021-21271","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21271"}],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0073","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Evidence Timestamp Inconsistency DoS","name":"evidence-timestamp-inconsistency-dos","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'evidence-timestamp-inconsistency-dos')","status":"active"},{"classification":"pending","display_name":"EVM Memory Corruption Consensus Split","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0074","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"EVM Memory Corruption Consensus Split","name":"evm-memory-corruption-consensus-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'evm-memory-corruption-consensus-split')","status":"active"},{"classification":"pending","display_name":"EVM Opcode/Precompile Semantics Divergence","external_references":[{"id":"CVE-2021-41153","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41153"}],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0075","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"EVM Opcode/Precompile Semantics Divergence","name":"evm-opcode-precompile-semantics-divergence","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'evm-opcode-precompile-semantics-divergence')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Expensive Debug RPC Compute Amplification","external_references":[],"family":"compute_amp","first_seen":"2026-07-01","id":"NRDAX-T0076","instances":[{"bundle_ref":"eth_debug_tracecall_calltracer_callframe_breadth_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_debug_tracecall_calltracer_callframe_breadth_amp"},{"bundle_ref":"eth_debug_tracecall_compute","chain":"ethereum","discovery_origin":"original-research","external_references":[{"id":"geth-debug-tracecall-compute-amplification","kind":"nr-brief","title":"How an exposed debug_traceCall lets one unauthenticated request burn seconds of go-ethereum CPU","url":"https://nullrabbit.ai/research/geth-debug-tracecall-compute-amplification"},{"id":"https://geth.ethereum.org/docs/interacting-with-geth/rpc","kind":"vendor-advisory","url":"https://geth.ethereum.org/docs/interacting-with-geth/rpc"}],"fidelity":"lab","primitive_id":"eth_debug_tracecall_compute"},{"bundle_ref":"eth_debug_tracecall_jstracer_perstep_opcode_cpu_burn","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_debug_tracecall_jstracer_perstep_opcode_cpu_burn"},{"bundle_ref":"eth_debug_tracecall_structlog_enablememory_quadratic_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_debug_tracecall_structlog_enablememory_quadratic_amp"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":4,"upper_bound":4},"mechanism":"debug_traceCall compute amplification (geth: debug API is DoS-prone, do not expose)","name":"expensive-debug-rpc-compute-amplification","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'expensive-debug-rpc-compute-amplification'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Fast Sync Pivot Failure Abort","external_references":[{"id":"GHPR-matter-labs-zksync-era-4247","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0077","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Fast Sync Pivot Failure Abort","name":"fast-sync-pivot-failure-abort","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'fast-sync-pivot-failure-abort')","status":"active"},{"classification":"pending","display_name":"Fee-Bump Replacement Policy Bypass","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0078","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Fee-Bump Replacement Policy Bypass","name":"fee-bump-policy-bypass","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'fee-bump-policy-bypass')","status":"active"},{"classification":"pending","display_name":"Field Element Comparison Bypass","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0079","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Field Element Comparison Bypass","name":"field-element-comparison-bypass","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'field-element-comparison-bypass')","status":"active"},{"classification":"pending","display_name":"Finality Justification Cache Bypass","external_references":[{"id":"CVE-2025-59941","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59941"}],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0080","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Finality Justification Cache Bypass","name":"finality-justification-cache-bypass","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'finality-justification-cache-bypass')","status":"active"},{"classification":"pending","display_name":"Force-Retire Integer Overflow Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0081","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Force-Retire Integer Overflow Crash","name":"force-retire-integer-overflow-crash","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'force-retire-integer-overflow-crash')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3003.001","name":"Long-Range Attack","url":"https://aadapt.mitre.org/techniques/ADT3003.001"},"display_name":"Forged Commit Future Height Light Client Attack","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0082","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Forged Commit Future Height Light Client Attack","name":"forged-commit-future-height-light-client-attack","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'forged-commit-future-height-light-client-attack')","status":"active"},{"classification":"pending","display_name":"Frame Parsing Memory Amplification","external_references":[{"id":"GHSA-4w2j-m93h-cj5j","kind":"ghsa","url":"https://github.com/advisories/GHSA-4w2j-m93h-cj5j"},{"id":"GHPR-Conflux-Chain-conflux-rust-3541","kind":"vendor-advisory"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0083","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Frame Parsing Memory Amplification","name":"frame-parsing-memory-amplification","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'frame-parsing-memory-amplification')","status":"active"},{"classification":"pending","display_name":"Gas Accounting Panic Bypass","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0084","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gas Accounting Panic Bypass","name":"gas-accounting-panic-bypass","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'gas-accounting-panic-bypass')","status":"active"},{"classification":"pending","display_name":"Gas Limit Capacity Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0085","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gas Limit Capacity Exhaustion","name":"gas-limit-capacity-exhaustion","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'gas-limit-capacity-exhaustion')","status":"active"},{"classification":"pending","display_name":"Gas Price Margin Integer Overflow","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0086","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gas Price Margin Integer Overflow","name":"gas-price-margin-integer-overflow","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'gas-price-margin-integer-overflow')","status":"active"},{"classification":"pending","display_name":"Genesis Migration Timing Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0087","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Genesis Migration Timing Panic","name":"genesis-migration-timing-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'genesis-migration-timing-panic')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"GetData Request Flood","dual_with":"response_amp","external_references":[],"family":"compute_amp","first_seen":"2026-07-01","id":"NRDAX-T0088","instances":[{"bundle_ref":"btc_getdata_flood","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/07/03/disclose-getdata-cpu/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/07/03/disclose-getdata-cpu/"}],"fidelity":"lab","primitive_id":"btc_getdata_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-52920 class: oversized GETDATA processing load","name":"getdata-request-flood","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'getdata-request-flood'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Gossip Attestation Index OOM","external_references":[{"id":"GHPR-sigp-lighthouse-9141","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0089","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gossip Attestation Index OOM","name":"gossip-attestation-index-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'gossip-attestation-index-oom')","status":"active"},{"classification":"pending","display_name":"Gossip Message Deadlock Stall","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0090","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gossip Message Deadlock Stall","name":"gossip-message-deadlock-stall","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'gossip-message-deadlock-stall')","status":"active"},{"classification":"pending","display_name":"Gossip Message Quarantine Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0091","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gossip Message Quarantine Crash","name":"gossip-message-quarantine-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'gossip-message-quarantine-crash')","status":"active"},{"classification":"pending","display_name":"Gossip Query Triggered DB Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0092","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gossip Query Triggered DB Crash","name":"gossip-query-triggered-db-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'gossip-query-triggered-db-crash')","status":"active"},{"classification":"pending","display_name":"Gossipsub Mcache Config Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0093","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gossipsub Mcache Config Panic Crash","name":"gossipsub-mcache-config-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'gossipsub-mcache-config-panic-crash')","status":"active"},{"classification":"pending","display_name":"Governance Proposal Panic Halt","external_references":[{"id":"GHSA-qr8r-m495-7hc4","kind":"ghsa","url":"https://github.com/advisories/GHSA-qr8r-m495-7hc4"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0094","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Governance Proposal Panic Halt","name":"governance-proposal-panic-halt","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'governance-proposal-panic-halt')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"GraphQL Alias Query Amplification","dual_with":"compute_amp","external_references":[{"id":"CVE-2023-42319","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42319"}],"family":"memory_amp","first_seen":"2023-01-01","id":"NRDAX-T0095","instances":[{"bundle_ref":"geth_graphql_aliased_logs_dos","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-v9jh-j8px-98vq","kind":"ghsa","url":"https://github.com/advisories/GHSA-v9jh-j8px-98vq"}],"fidelity":"lab","primitive_id":"geth_graphql_aliased_logs_dos"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2023-42319: geth <=1.13.4 --http --graphql; a query with N aliased logs(filter:{fromBlock:0}) ops -> unbounded per-alias full-chain scan -> memory blowup","name":"graphql-alias-query-amplification","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'graphql-alias-query-amplification'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"GraphQL Nested Query Depth CPU Exhaustion","external_references":[{"id":"GHPR-ethereum-go-ethereum-32344","kind":"vendor-advisory"}],"family":null,"first_seen":"2026-07-21","id":"NRDAX-T0096","instances":[{"bundle_ref":"geth_graphql_query_depth_stack_overflow","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"geth_graphql_query_depth_stack_overflow"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"go-ethereum#32344 (geth graphql): a single unauthenticated HTTP POST to /graphql carrying a deeply-nested query `{block{ommers{ommers{...}}}}` is parsed with unbounded nesting depth by graph-gophers/graphql-go; a sufficiently deep query (~1e6 levels) drives recursive-descent parsing past Go's 1 GiB goroutine-stack limit -> `fatal error: stack overflow` -> the geth process crashes (remote DoS). Verified live vs a pre-fix geth (commit dffa1f51): depth 1e6 kills the node. Fixed by graphql.MaxDepth(20). https://github.com/ethereum/go-ethereum/pull/32344","name":"graphql-nested-query-depth-cpu-exhaustion","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'graphql-nested-query-depth-cpu-exhaustion'","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"gRPC/H2 Multiplexing OOM","external_references":[],"family":"memory_amp","first_seen":"2026-07-03","id":"NRDAX-T0097","instances":[{"bundle_ref":"iota_grpc_h2_multiplex_oom","chain":"iota","discovery_origin":"original-research","external_references":[{"id":"iota-node-grpc-unbounded-http2-streams-oom","kind":"nr-brief","title":"How unbounded HTTP/2 concurrent streams let one TCP connection OOM-kill an IOTA node's public gRPC server","url":"https://nullrabbit.ai/research/iota-node-grpc-unbounded-http2-streams-oom"},{"id":"https://github.com/iotaledger/iota","kind":"vendor-advisory","url":"https://github.com/iotaledger/iota"}],"fidelity":"lab","primitive_id":"iota_grpc_h2_multiplex_oom"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"NullRabbit measurement (gRPC/h2 multiplex DoS).","name":"grpc-h2-multiplexing-oom","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'grpc-h2-multiplexing-oom'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Guest Module Memory Corruption","external_references":[{"id":"CVE-2024-38533","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-38533"}],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0098","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Guest Module Memory Corruption","name":"guest-module-memory-corruption","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'guest-module-memory-corruption')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Half-Open Handshake Slowloris","dual_with":"memory_amp","external_references":[],"family":"connection_exhaustion","first_seen":"2026-07-01","id":"NRDAX-T0099","instances":[{"bundle_ref":"ic_quic_halfopen_pin","chain":"ic","discovery_origin":"original-research","external_references":[{"id":"https://github.com/dfinity/ic","kind":"vendor-advisory","url":"https://github.com/dfinity/ic — rs/p2p/quic_transport/src/connection_manager.rs: the accept loop spawns every inbound QUIC Initial into an UNBOUNDED `inbound_connecting` JoinSet with `EndpointConfig::default()` (no Retry / no address validation) and NO per-source-IP UDP pre-handshake budget (`max_simultaneous_connections_per_ip_address` is TCP-only). The mTLS NodeId allow-list is enforced only AFTER the per-connection quinn/rustls state is committed, so certificate trust does not mitigate the pre-handshake pin."}],"fidelity":"lab","primitive_id":"ic_quic_halfopen_pin"},{"bundle_ref":"iota_http_tls_halfopen_plaintext_grpc","chain":"iota","discovery_origin":"original-research","external_references":[{"id":"https://github.com/iotaledger/iota","kind":"vendor-advisory","url":"https://github.com/iotaledger/iota — iota-http/src/config.rs (NO tls_handshake_timeout field, NO max_pending_connections field) + iota-http/src/lib.rs:281-313 accept loop (tokio::spawn { tls_acceptor.accept(io).await } with no deadline, spawned into an unbounded JoinSet) + iota-network-stack/src/server.rs:76 ServerBuilder::new().allow_insecure(true) (validator gRPC accepts plaintext h2c). cf. Sui post-#26069 which added tls_handshake_timeout=Some(5s) + max_pending_connections=Some(4096) and removed allow_insecure."}],"fidelity":"lab","primitive_id":"iota_http_tls_halfopen_plaintext_grpc"},{"bundle_ref":"near_handshake_preauth_pending_starvation","chain":"near","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"near_handshake_preauth_pending_starvation"},{"bundle_ref":"sol_tpu_quic_handshake_flood","chain":"solana","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://neodyme.io/reports/Firedancer-v0.4.pdf","kind":"vendor-advisory","url":"https://neodyme.io/reports/Firedancer-v0.4.pdf"}],"fidelity":"lab","primitive_id":"sol_tpu_quic_handshake_flood"},{"bundle_ref":"sol_tpu_quic_slowloris","chain":"solana","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://neodyme.io/reports/Firedancer-v0.4.pdf","kind":"vendor-advisory","url":"https://neodyme.io/reports/Firedancer-v0.4.pdf"}],"fidelity":"lab","primitive_id":"sol_tpu_quic_slowloris"},{"bundle_ref":"rippled_tls_slow_handshake","chain":"xrp","discovery_origin":"original-research","external_references":[{"id":"rippled-tls-handshake-slowloris-fd-exhaustion","kind":"nr-brief","title":"How an unauthenticated TLS half-open flood pins rippled's memory and crashes it under low file-descriptor limits","url":"https://nullrabbit.ai/research/rippled-tls-handshake-slowloris-fd-exhaustion"},{"id":"https://github.com/XRPLF/rippled","kind":"vendor-advisory","url":"https://github.com/XRPLF/rippled — inbound peer TLS listener OverlayImpl::onHandoff (boost::asio::ssl::stream::async_handshake, peer port 51235) + JSON-RPC HTTPS listener (port 5006): no handshake deadline (cf. outbound ConnectAttempt.cpp:153), no per-IP half-open cap (Resource::Consumer OverlayImpl.cpp:235 gates rate not count)."}],"fidelity":"lab","primitive_id":"rippled_tls_slow_handshake"}],"lineage":{"deployments":5,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":6,"upper_bound":6},"mechanism":"IC quic_transport half-open QUIC handshake memory pin (IC_QUIC_HALFOPEN_PIN): a burst of QUIC v1 Initial packets (distinct SCID each) whose CRYPTO frame declares a large TLS handshake length (4096) but delivers a truncated ClientHello (~200 B) leaves rustls 'incomplete, waiting', so each `Connecting` future lives to the pre-handshake timeout pinning ~100 KiB/conn. No Retry (EndpointConfig::default()), no per-IP UDP cap, mTLS only after state is committed. Measured on the real replica (release-2026-05-29_04-44-base, commit a47e543, 2026-06-02): n=200 -> +25.5 MiB (~128 KiB/conn), n=1000 -> +129 MiB (~132 KiB/conn), n=3000 -> +278 MiB (abs 420 MiB, ~95 KiB/conn); across 12,200 total connections ZERO were rejected at admission. MEDIUM/5.9 (bounded only by IC's default-deny firewall + 512 GiB replica RAM, not by any transport control). NullRabbit measurement; chains/ic/findings/IC_QUIC_HALFOPEN_PIN.","name":"half-open-handshake-slowloris","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'half-open-handshake-slowloris'","status":"active","surface":"p2p-gossip"},{"bound_failure":"late","classification":"curated","display_name":"Handshake Crypto CPU Burn","external_references":[{"id":"CVE-2023-39533","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39533"},{"id":"CVE-2025-29606","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29606"}],"family":"compute_amp","first_seen":"2023-01-01","id":"NRDAX-T0100","instances":[{"bundle_ref":"bsc_rlpx_auth_flood","chain":"bnb-smart-chain","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"bsc_rlpx_auth_flood"},{"bundle_ref":"celestia_libp2p_noise_preauth_flood","chain":"celestia","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"celestia_libp2p_noise_preauth_flood"},{"bundle_ref":"ethcl_libp2p_noise_preauth_flood","chain":"ethereum-consensus-layer","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"ethcl_libp2p_noise_preauth_flood"},{"bundle_ref":"fil_libp2p_noise_preauth_flood","chain":"filecoin","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"fil_libp2p_noise_preauth_flood"},{"bundle_ref":"op_libp2p_noise_preauth_flood","chain":"optimism","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"op_libp2p_noise_preauth_flood"},{"bundle_ref":"substrate_litep2p_noise_preauth_flood","chain":"polkadot-substrate","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"substrate_litep2p_noise_preauth_flood"},{"bundle_ref":"bor_rlpx_auth_flood","chain":"polygon-pos","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"bor_rlpx_auth_flood"},{"bundle_ref":"sol_tpu_quic_initial_cpu","chain":"solana","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://neodyme.io/reports/Firedancer.pdf","kind":"vendor-advisory","url":"https://neodyme.io/reports/Firedancer.pdf"}],"fidelity":"lab","primitive_id":"sol_tpu_quic_initial_cpu"},{"bundle_ref":"sonic_rlpx_auth_flood","chain":"sonic-fantom","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"sonic_rlpx_auth_flood"}],"lineage":{"deployments":9,"groups":["libp2p-noise","litep2p-noise","rlpx","solana-tpu-quic"],"independent_stacks":4,"is_lower_bound":false,"unknown_instances":0,"upper_bound":4},"mechanism":"Neodyme ND-FD1-MD-02: QUIC INITIAL flood → per-handshake x25519 + ed25519 sign-tile CPU exhaustion (compute-bound, distinct from the connection-slot flood)","name":"handshake-crypto-cpu-burn","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'handshake-crypto-cpu-burn'","status":"active","surface":"p2p-gossip"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Handshake Crypto Validation Bypass Crash","external_references":[],"family":"fault_termination","first_seen":"2026-07-07","id":"NRDAX-T0101","instances":[{"bundle_ref":"geth_auth_zero_pubkey","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-q26p-9cq4-7fc2","kind":"ghsa","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-q26p-9cq4-7fc2"}],"fidelity":"lab","primitive_id":"geth_auth_zero_pubkey"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2025-24883: RLPx auth with an all-zero (off-curve) EC pubkey — geth <1.14.13 skips the secp256k1 point-validity check → handshake crypto crash (fixed 159fb1a)","name":"handshake-crypto-validation-bypass-crash","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'handshake-crypto-validation-bypass-crash'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Handshake Key Validation Info Leak","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0102","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Handshake Key Validation Info Leak","name":"handshake-key-validation-info-leak","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'handshake-key-validation-info-leak')","status":"active"},{"classification":"pending","display_name":"Handshake Version String Crash","external_references":[{"id":"GHREL-firedancer-io-firedancer-v1.1.2","kind":"vendor-advisory"},{"id":"GHREL-near-nearcore-1.36.3","kind":"vendor-advisory"},{"id":"GHREL-near-nearcore-1.36.4","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0103","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Handshake Version String Crash","name":"handshake-version-string-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'handshake-version-string-crash')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3016.001","name":"Cryptographic Protocol Analysis","url":"https://aadapt.mitre.org/techniques/ADT3016.001"},"display_name":"Hash Collision Forgery","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0104","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Hash Collision Forgery","name":"hash-collision-forgery","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'hash-collision-forgery')","status":"active"},{"classification":"pending","display_name":"Hash Function Overflow Misbehavior","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0105","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Hash Function Overflow Misbehavior","name":"hash-function-overflow-misbehavior","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'hash-function-overflow-misbehavior')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Header-Length Preallocation OOM","external_references":[],"family":"memory_amp","first_seen":"2026-07-01","id":"NRDAX-T0106","instances":[{"bundle_ref":"btc_oversized_recv_buffer","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/07/03/disclose_receive_buffer_oom/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/07/03/disclose_receive_buffer_oom/"}],"fidelity":"lab","primitive_id":"btc_oversized_recv_buffer"},{"bundle_ref":"yamux_syn_oversized_body_panic","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"yamux_syn_oversized_body_panic"},{"bundle_ref":"monero_portable_storage_oom","chain":"monero","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/monero-project/monero/pull/7190","kind":"vendor-advisory","url":"https://github.com/monero-project/monero/pull/7190"}],"fidelity":"lab","primitive_id":"monero_portable_storage_oom"},{"bundle_ref":"zcash_zebra_addr_vector_preallocation_amplification","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-xr93-pcq3-pxf8","kind":"ghsa","url":"https://github.com/advisories/GHSA-xr93-pcq3-pxf8"}],"fidelity":"lab","primitive_id":"zcash_zebra_addr_vector_preallocation_amplification"},{"bundle_ref":"zcash_zebra_coinbase_script_preallocation_amplification","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-44500","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44500"}],"fidelity":"lab","primitive_id":"zcash_zebra_coinbase_script_preallocation_amplification"},{"bundle_ref":"zcash_zebra_equihash_solution_preallocation_amplification","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-44500","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44500"}],"fidelity":"lab","primitive_id":"zcash_zebra_equihash_solution_preallocation_amplification"},{"bundle_ref":"zcash_zebra_headers_message_preallocation_amplification","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-44500","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44500"}],"fidelity":"lab","primitive_id":"zcash_zebra_headers_message_preallocation_amplification"}],"lineage":{"deployments":4,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":7,"upper_bound":7},"mechanism":"CVE-2015-3641: header length field pre-allocates the receive buffer before the body → per-connection OOM","name":"header-length-preallocation-oom","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'header-length-preallocation-oom'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Headers Message Flood OOM","external_references":[{"id":"CVE-2019-25220","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-25220"},{"id":"CVE-2024-52916","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52916"}],"family":null,"first_seen":"2019-01-01","id":"NRDAX-T0107","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Headers Message Flood OOM","name":"headers-message-flood-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'headers-message-flood-oom')","status":"active"},{"classification":"pending","display_name":"HTLC Replay Init Order Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0108","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"HTLC Replay Init Order Crash","name":"htlc-replay-init-order-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'htlc-replay-init-order-crash')","status":"active"},{"classification":"pending","display_name":"HTTP API Connection Hang DoS","external_references":[{"id":"CVE-2021-21369","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21369"}],"family":null,"first_seen":"2017-01-01","id":"NRDAX-T0109","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"HTTP API Connection Hang DoS","name":"http-api-connection-hang-dos","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'http-api-connection-hang-dos')","status":"active"},{"classification":"pending","display_name":"HTTP Header Spoofing Trust Bypass","external_references":[{"id":"CVE-2026-49353","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49353"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0110","instances":[{"bundle_ref":"eth_geth_h2h1_empty_authority_vhost_bypass","chain":"ethereum","discovery_origin":"original-research","external_references":[{"id":"geth-http-vhosts-empty-host-allowlist-bypass","kind":"nr-brief","title":"Bypassing go-ethereum's --http.vhosts host allowlist with an empty Host, forged by an HAProxy HTTP/2→1.1 downgrade","url":"https://nullrabbit.ai/research/geth-http-vhosts-empty-host-allowlist-bypass"}],"fidelity":"lab","primitive_id":"eth_geth_h2h1_empty_authority_vhost_bypass"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The defect is geth's --http.vhosts allowlist treating an empty/absent Host header as implicitly trusted rather than explicitly denying it, combined with an HAProxy h2->h1 downgrade path that forwards HTTP/2 requests with an empty :authority as an empty Host instead of rejecting or filling it. An attacker with raw-h2 capability sends a request with :authority=\"\" through the HAProxy front; HAProxy forwards it as empty Host while a normal forbidden hostname would be rejected with 403. The measurable effect is a 200 response bypassing the vhost/anti-DNS-rebinding allowlist, granting access that the Host-based authorization was meant to block.","name":"http-header-spoofing-trust-bypass","producer_family":"auth_bypass","provenance_note":"imported from nr_registry cluster 'http-header-spoofing-trust-bypass'","status":"active"},{"classification":"pending","display_name":"HTTP/2 Rapid Reset Memory Exhaustion","external_references":[{"id":"CVE-2023-26964","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26964"}],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0111","instances":[{"bundle_ref":"http2_madeyoureset_flood","chain":"http2","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"http2_madeyoureset_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2025-8671 \"MadeYouReset\" (CVE-2025-55163 / GHSA-prj3-ccx8-p6x4 / VU#767506): an unauthenticated attacker opens an HTTP/2 stream (HEADERS, END_STREAM — a complete request) and then sends a protocol-valid-but-misused control frame — this driver uses WINDOW_UPDATE with a flow-control increment of 0 (a stream error PROTOCOL_ERROR per RFC 9113 §6.9.1) — which forces the SERVER to emit RST_STREAM. Because a reset stream is immediately no longer counted as active, the server's MAX_CONCURRENT_STREAMS ceiling (typ. 100) is never reached, yet the backend has already been handed the request and keeps processing it. Repeating the HEADERS+WINDOW_UPDATE(0) cycle floods the server with unbounded concurrent backend work -> memory/CPU exhaustion -> OOM / CPU-pin -> DoS (Tomcat manifests as OutOfMemoryError). This is DISTINCT from CVE-2023-44487 HTTP/2 Rapid Reset: there the CLIENT sends RST_STREAM, so the reset frames are inbound and rate-limitable; here the RST_STREAM is SERVER-emitted (outbound), so the post-CVE-2023-44487 client-side rapid-reset mitigations do not apply. Faithful known-class replication of the MadeYouReset wire signature (HEADERS+END_STREAM, then WINDOW_UPDATE with a zero increment, then a server-emitted RST_STREAM); the OOM/CPU impact is the CVE's, not reproduced against a live server. source_class=public-cve-replication. Distinct wire signature from the sibling rapid-reset drivers (walrus_http2_rapid_reset / substrate_h2_rapid_reset), which are CLIENT-emitted RST.","name":"http2-rapid-reset-memory-exhaustion","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'http2-rapid-reset-memory-exhaustion'","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"HTTP/2 Rapid Reset Stream Exhaustion","external_references":[{"id":"CVE-2023-44487","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44487"}],"family":"memory_amp","first_seen":"2023-01-01","id":"NRDAX-T0112","instances":[{"bundle_ref":"substrate_h2_rapid_reset","chain":"polkadot","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2023-26964","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-26964"}],"fidelity":"lab","primitive_id":"substrate_h2_rapid_reset"},{"bundle_ref":"walrus_http2_rapid_reset","chain":"walrus","discovery_origin":"original-research","external_references":[{"id":"CVE-2023-44487","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-44487"}],"fidelity":"lab","primitive_id":"walrus_http2_rapid_reset"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2023-26964 (RUSTSEC-2023-0034): the Rust h2 crate < 0.3.17 does not release stream memory immediately on RST_STREAM and — pre-0.3.17 — has NO bound on streams in the pending-accept-but-remotely-reset state. An unauthenticated attacker cycles HEADERS(open stream)->RST_STREAM(cancel) faster than the application accepts requests off the queue; the queue grows unbounded -> excessive memory + CPU -> OOM (HTTP/2 Rapid Reset, CVE-2023-44487 class). Substrate/polkadot consumed h2 0.3.16 (indirect dep via hyper) on the node JSON-RPC HTTP server (jsonrpsee) and the prometheus monitoring endpoint until paritytech/substrate#13915 bumped it to 0.3.17. The fix (hyperium/h2#668) ADDS max_pending_accept_reset_streams and, on hitting the limit, sends GOAWAY(ENHANCE_YOUR_CALM) and errors the connection — behaviour the vulnerable versions lack, so a pre-0.3.17 server never issues GOAWAY. Network-triggered, availability-only (CVSS 7.5, AV:N/A:H). Faithful known-class replication of the HEADERS+RST_STREAM rapid-reset wire signature; the OOM impact is the CVE's, not reproduced against a live node. source_class=public-cve-replication. Distinct target from walrus_http2_rapid_reset (which is a walrus config disabling an EXISTING h2 limit; here the crate itself has no limit).","name":"http2-rapid-reset-stream-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'http2-rapid-reset-stream-exhaustion'","status":"active","surface":"rpc-api"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012.005","name":"Reentrancy","url":"https://aadapt.mitre.org/techniques/ADT3012.005"},"display_name":"IBC Timeout Callback Reentrancy","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0113","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"IBC Timeout Callback Reentrancy","name":"ibc-timeout-callback-reentrancy","out_of_scope":true,"producer_family":"bridge","provenance_note":"known-but-not-reproduced coverage gap (technique 'ibc-timeout-callback-reentrancy')","status":"active"},{"classification":"pending","display_name":"ICMP PMTUD Injection Disruption","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0114","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"ICMP PMTUD Injection Disruption","name":"icmp-pmtud-injection-disruption","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'icmp-pmtud-injection-disruption')","status":"active"},{"classification":"pending","display_name":"Implementation Divergence Chain Split","external_references":[{"id":"CVE-2020-26241","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26241"},{"id":"CVE-2020-26265","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26265"},{"id":"GHSA-cwfq-rfcr-8hmp","kind":"ghsa","url":"https://github.com/advisories/GHSA-cwfq-rfcr-8hmp"},{"id":"GHSA-pvmv-cwg8-v6c8","kind":"ghsa","url":"https://github.com/advisories/GHSA-pvmv-cwg8-v6c8"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0115","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Implementation Divergence Chain Split","name":"implementation-divergence-chain-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'implementation-divergence-chain-split')","status":"active"},{"classification":"pending","display_name":"Incomplete Packet Timer Overflow CPU Burn","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0116","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Incomplete Packet Timer Overflow CPU Burn","name":"incomplete-packet-timer-overflow-cpu-burn","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'incomplete-packet-timer-overflow-cpu-burn')","status":"active"},{"classification":"pending","display_name":"Index Out-Of-Bounds Panic Crash","external_references":[{"id":"GHPR-cosmos-cosmos-sdk-26515","kind":"vendor-advisory"},{"id":"GHPR-cosmos-cosmos-sdk-26517","kind":"vendor-advisory"},{"id":"GHPR-cosmos-cosmos-sdk-26573","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0117","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Index Out-Of-Bounds Panic Crash","name":"index-oob-panic-crash","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'index-oob-panic-crash')","status":"active"},{"classification":"pending","display_name":"Integer Overflow Consensus Split","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0118","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Integer Overflow Consensus Split","name":"integer-overflow-consensus-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'integer-overflow-consensus-split')","status":"active"},{"classification":"pending","display_name":"Integer Overflow Decompression Infinite Loop","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0119","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Integer Overflow Decompression Infinite Loop","name":"integer-overflow-decompression-infinite-loop","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'integer-overflow-decompression-infinite-loop')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Integer-Overflow Panic Control Message","external_references":[{"id":"CVE-2018-12018","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12018"},{"id":"CVE-2025-46597","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46597"},{"id":"CVE-2026-31814","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31814"},{"id":"CVE-2026-33040","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33040"},{"id":"CVE-2026-34219","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34219"},{"id":"GHPR-Conflux-Chain-conflux-rust-3504","kind":"vendor-advisory"},{"id":"GHPR-Conflux-Chain-conflux-rust-3532","kind":"vendor-advisory"},{"id":"GHPR-libp2p-rust-libp2p-6467","kind":"vendor-advisory"},{"id":"GHPR-near-nearcore-15921","kind":"vendor-advisory"}],"family":"fault_termination","first_seen":"2018-01-01","id":"NRDAX-T0120","instances":[{"bundle_ref":"gossipsub_prune_backoff_overflow","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-xqmp-fxgv-xvq5","kind":"ghsa","url":"https://github.com/libp2p/rust-libp2p/security/advisories/GHSA-xqmp-fxgv-xvq5"},{"id":"rust-libp2p-gossipsub-prune-backoff-overflow-cve-2026-34219","kind":"nr-brief","title":"How a single crafted gossipsub PRUNE backoff value panics rust-libp2p nodes via an Instant overflow (CVE-2026-34219)","url":"https://nullrabbit.ai/research/rust-libp2p-gossipsub-prune-backoff-overflow-cve-2026-34219"}],"fidelity":"lab","primitive_id":"gossipsub_prune_backoff_overflow"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2026-34219 (+CVE-2026-33040): gossipsub ControlPrune backoff≈u64::MAX → Instant/Duration overflow panic","name":"integer-overflow-panic-control-message","producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'integer-overflow-panic-control-message'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Integer Overflow Parsing Crash","external_references":[{"id":"GHSA-82vg-5v4f-f9wq","kind":"ghsa","url":"https://github.com/advisories/GHSA-82vg-5v4f-f9wq"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0121","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Integer Overflow Parsing Crash","name":"integer-overflow-parsing-crash","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'integer-overflow-parsing-crash')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Integer Signedness Index OOB Crash","external_references":[],"family":"fault_termination","first_seen":"2026-07-07","id":"NRDAX-T0122","instances":[{"bundle_ref":"conflux_getblocktxn_index_overflow","chain":"conflux","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/Conflux-Chain/conflux-rust/pull/3509","kind":"vendor-advisory","url":"https://github.com/Conflux-Chain/conflux-rust/pull/3509"}],"fidelity":"lab","primitive_id":"conflux_getblocktxn_index_overflow"},{"bundle_ref":"cosmos_gogoproto_skippy","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2021-3121","kind":"cve","url":"https://osv.dev/vulnerability/CVE-2021-3121"}],"fidelity":"lab","primitive_id":"cosmos_gogoproto_skippy"},{"bundle_ref":"geth_les_skip_negative","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2018-12018","kind":"cve","url":"https://peckshield.medium.com/epod-ethereum-packet-of-death-cve-2018-12018-fc9ee944843e"}],"fidelity":"lab","primitive_id":"geth_les_skip_negative"}],"lineage":{"deployments":3,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"CVE-2021-3121 (gogoproto 'skippy peanut butter'): unknown length-delimited field with a negative-length varint → pre-1.3.2 skip code does iNdEx+=length with no length<0 check → index out of bounds → panic in the cosmos-sdk tx decoder, pre-signature-validation","name":"integer-signedness-index-oob-crash","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'integer-signedness-index-oob-crash'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Interlink Mismatch Consensus Failure","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0123","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Interlink Mismatch Consensus Failure","name":"interlink-mismatch-consensus-failure","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'interlink-mismatch-consensus-failure')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"INV Flood GetHeaders Amplification","external_references":[],"family":"response_amp","first_seen":"2026-07-01","id":"NRDAX-T0124","instances":[{"bundle_ref":"btc_inv_buffer_blowup","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/07/03/disclose-inv-buffer-blowup/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/07/03/disclose-inv-buffer-blowup/"}],"fidelity":"lab","primitive_id":"btc_inv_buffer_blowup"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-52915: INV with 50k items → 50k getheaders replies / send-buffer blowup","name":"inv-flood-getheaders-amplification","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'inv-flood-getheaders-amplification'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Inv Message Flood OOM","external_references":[{"id":"CVE-2018-12356","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-12356"},{"id":"CVE-2018-17145","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-17145"},{"id":"CVE-2024-52915","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52915"}],"family":null,"first_seen":"2018-01-01","id":"NRDAX-T0125","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Inv Message Flood OOM","name":"inv-message-flood-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'inv-message-flood-oom')","status":"active"},{"classification":"pending","display_name":"Inv Queue Draining CPU DoS","external_references":[{"id":"CVE-2023-33297","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33297"}],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0126","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Inv Queue Draining CPU DoS","name":"inv-queue-draining-cpu-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'inv-queue-draining-cpu-dos')","status":"active"},{"classification":"pending","display_name":"Invalid Address Nil-Pointer Crash","external_references":[{"id":"GHPR-libp2p-go-libp2p-3395","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0127","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Invalid Address Nil-Pointer Crash","name":"invalid-address-nil-pointer-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'invalid-address-nil-pointer-crash')","status":"active"},{"classification":"pending","display_name":"Invalid Commit Signature Halt","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0128","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Invalid Commit Signature Halt","name":"invalid-commit-signature-halt","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'invalid-commit-signature-halt')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Invalid Curve Point Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-07","id":"NRDAX-T0129","instances":[{"bundle_ref":"zcash_zebra_orchard_rk_identity_verify_panic","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-452v-w3gx-72wg","kind":"ghsa","url":"https://github.com/advisories/GHSA-452v-w3gx-72wg"}],"fidelity":"lab","primitive_id":"zcash_zebra_orchard_rk_identity_verify_panic"},{"bundle_ref":"zcash_zebra_v5_orchard_rk_noncanonical_txid_panic","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-34202","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34202"}],"fidelity":"lab","primitive_id":"zcash_zebra_v5_orchard_rk_noncanonical_txid_panic"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2026-41584 (GHSA-452v-w3gx-72wg): a V5/NU5 tx whose Orchard action rk is the IDENTITY point [0x00;32] — a canonical point the spec allows, so it passes parse + hash() — but Orchard proof verification extracts the identity's affine coords and .unwrap()s (circuit.rs Instance::to_halo2_instance) → PANIC. Single unauth P2P tx crashes the node in verify. Fixed v4.3.1 / zebra-chain 6.0.2.","name":"invalid-curve-point-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'invalid-curve-point-panic'","status":"active","surface":"consensus-ingest"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3007","name":"Exploit Consensus Logic","url":"https://aadapt.mitre.org/techniques/ADT3007"},"display_name":"Invalid Finality Signature Bypass","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0130","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Invalid Finality Signature Bypass","name":"invalid-finality-signature-bypass","out_of_scope":true,"producer_family":"bridge","provenance_note":"known-but-not-reproduced coverage gap (technique 'invalid-finality-signature-bypass')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Invalid Message Log Flood","external_references":[],"family":"memory_amp","first_seen":"2026-07-01","id":"NRDAX-T0131","instances":[{"bundle_ref":"btc_invalid_block_logfill","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-54605","kind":"cve","url":"https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-54605/"}],"fidelity":"lab","primitive_id":"btc_invalid_block_logfill"},{"bundle_ref":"btc_version_selfnonce","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-54604","kind":"cve","url":"https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-54604/"}],"fidelity":"lab","primitive_id":"btc_version_selfnonce"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2025-54605: flood of PoW-invalid blocks logged unconditionally → log/disk fill","name":"invalid-message-log-flood","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'invalid-message-log-flood'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Invariant Check Spam CPU Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0132","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Invariant Check Spam CPU Exhaustion","name":"invariant-check-spam-cpu-exhaustion","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'invariant-check-spam-cpu-exhaustion')","status":"active"},{"classification":"pending","display_name":"Iterator Length Mismatch Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0133","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Iterator Length Mismatch Panic","name":"iterator-length-mismatch-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'iterator-length-mismatch-panic')","status":"active"},{"classification":"pending","display_name":"JSON Deserialization RCE","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0134","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"JSON Deserialization RCE","name":"json-deserialization-rce","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'json-deserialization-rce')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3003","name":"Chain Reorganization","url":"https://aadapt.mitre.org/techniques/ADT3003"},"display_name":"L1 Finality Assumption Reorg","external_references":[{"id":"CVE-2025-48886","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48886"}],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0135","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"L1 Finality Assumption Reorg","name":"l1-finality-assumption-reorg","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'l1-finality-assumption-reorg')","status":"active"},{"classification":"pending","display_name":"Large Trie Commit Batch Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0136","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Large Trie Commit Batch Panic Crash","name":"large-trie-commit-batch-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'large-trie-commit-batch-panic-crash')","status":"active"},{"classification":"pending","display_name":"Latent Consensus Decision Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0137","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Latent Consensus Decision Panic","name":"latent-consensus-decision-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'latent-consensus-decision-panic')","status":"active"},{"classification":"pending","display_name":"Leader Election Manipulation Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0138","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Leader Election Manipulation Panic","name":"leader-election-manipulation-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'leader-election-manipulation-panic')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Legacy Sighash Quadratic CPU Blowup","external_references":[],"family":"compute_amp","first_seen":"2026-07-01","id":"NRDAX-T0139","instances":[{"bundle_ref":"btc_tx_quad_sighash","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-46598","kind":"cve","url":"https://bitcoincore.org/en/2025/10/24/disclose-cve-2025-46598/"}],"fidelity":"lab","primitive_id":"btc_tx_quad_sighash"},{"bundle_ref":"namada_tx_repeated_sections_hash_blowup","chain":"namada","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"namada_tx_repeated_sections_hash_blowup"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2025-46598: non-standard tx with many legacy-sighash inputs → quadratic validation CPU, no peer penalty","name":"legacy-sighash-quadratic-cpu-blowup","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'legacy-sighash-quadratic-cpu-blowup'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Log Injection RCE","external_references":[{"id":"CVE-2021-44228","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44228"}],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0140","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Log Injection RCE","name":"log-injection-rce","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'log-injection-rce')","status":"active"},{"classification":"pending","display_name":"Low-Fee Transaction Spam Flood","external_references":[{"id":"CVE-2019-11636","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11636"}],"family":null,"first_seen":"2019-01-01","id":"NRDAX-T0141","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Low-Fee Transaction Spam Flood","name":"low-fee-tx-spam-flood","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'low-fee-tx-spam-flood')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Malformed Bytecode Index Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-02","id":"NRDAX-T0142","instances":[{"bundle_ref":"sui_disassemble_panic","chain":"sui","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://medium.com/certik-skyfall/blockchain-rpc-vulnerabilities-why-memory-safe-blockchain-rpc-nodes-are-not-panic-free-9fbb990115e0","kind":"vendor-advisory","url":"https://medium.com/certik-skyfall/blockchain-rpc-vulnerabilities-why-memory-safe-blockchain-rpc-nodes-are-not-panic-free-9fbb990115e0"}],"fidelity":"lab","primitive_id":"sui_disassemble_panic"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CertiK Skyfall: Publish RPC disassembles a malformed Move module (empty code_unit) → index panic → RPC crash","name":"malformed-bytecode-index-panic","producer_family":"rpc_handler_cpu","provenance_note":"imported from nr_registry cluster 'malformed-bytecode-index-panic'","status":"active","surface":"rpc-api"},{"bound_failure":"late","classification":"curated","display_name":"Malformed Field Gossip Before Validation","external_references":[],"family":"compute_amp","first_seen":"2026-07-07","id":"NRDAX-T0143","instances":[{"bundle_ref":"cometbft_bitarray_mismatch","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-hrhf-2vcr-ghch","kind":"ghsa","url":"https://github.com/cometbft/cometbft/security/advisories/GHSA-hrhf-2vcr-ghch"}],"fidelity":"lab","primitive_id":"cometbft_bitarray_mismatch"},{"bundle_ref":"cometbft_blockpart_mismatch","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-r3r4-g7hq-pq4f","kind":"ghsa","url":"https://github.com/advisories/GHSA-r3r4-g7hq-pq4f"}],"fidelity":"lab","primitive_id":"cometbft_blockpart_mismatch"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"GHSA-hrhf-2vcr-ghch (ASA-2025-003): a BitArray whose declared Bits does not match its Elems count (len(Elems) != ceil(Bits/64)) is processed in an invalid state and gossiped to peers before validation → network halt (VoteSetBits channel 0x23; fixed v0.38.19 / v0.37.16).","name":"malformed-field-gossip-before-validation","producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'malformed-field-gossip-before-validation'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Malformed GETDATA Infinite Loop","external_references":[{"id":"CVE-2024-52920","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52920"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0144","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Malformed GETDATA Infinite Loop","name":"malformed-getdata-infinite-loop","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'malformed-getdata-infinite-loop')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Malformed HTTP Body Crash","external_references":[],"family":"fault_termination","first_seen":"2026-07-09","id":"NRDAX-T0145","instances":[{"bundle_ref":"zebra_rpc_premature_disconnect_crash","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-41585","kind":"cve","url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-29x4-r6jv-ff4w"}],"fidelity":"lab","primitive_id":"zebra_rpc_premature_disconnect_crash"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2026-41585 (GHSA-29x4-r6jv-ff4w): Zebra's JSON-RPC HTTP middleware treated a failure to read the incoming HTTP request body as an unrecoverable error, aborting the process instead of returning an error response. A client that opens the RPC HTTP connection, sends headers (Content-Length promising the full JSON-RPC body) plus only a PARTIAL body, then RSTs the socket mid-transfer (premature disconnect) crashes the node; an authenticated attacker repeats it to hold the node in a crash/restart loop -> availability DoS. Requires a client that can pass cookie auth (on by default). Affected: zebrad 2.2.0 .. <4.3.1 (through 4.3.0), zebra-rpc 1.0.0-beta.45 .. <6.0.2 (through 6.0.1). Fixed: zebrad 4.3.1 / zebra-rpc 6.0.2 (body-read failure now propagated as an ordinary error response).","name":"malformed-http-body-crash","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'malformed-http-body-crash'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Malformed HTTP Header Parsing Crash","external_references":[{"id":"GHPR-stellar-stellar-core-5149","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0146","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Malformed HTTP Header Parsing Crash","name":"malformed-http-header-parsing-crash","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'malformed-http-header-parsing-crash')","status":"active"},{"classification":"pending","display_name":"Malformed HTTP/3 Frame Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0147","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Malformed HTTP/3 Frame Crash","name":"malformed-http3-frame-crash","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'malformed-http3-frame-crash')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Malformed KZG Proof Mismatch DoS","external_references":[],"family":"compute_amp","first_seen":"2026-07-07","id":"NRDAX-T0148","instances":[{"bundle_ref":"geth_blob_kzg_dos","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-mq3p-rrmp-79jg","kind":"ghsa","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-mq3p-rrmp-79jg"}],"fidelity":"lab","primitive_id":"geth_blob_kzg_dos"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2026-22868 (CVSS 7.5): a batch of EIP-4844 type-3 blob txs announced then delivered (PooledTransactions) with structurally-valid KZG sidecars whose commitment/proof (over blob A) mismatch the carried blob (B) — geth <1.16.8 runs the full KZG proof pairing on EVERY tx in the batch before any validity check, so a malicious peer forces per-tx cryptographic verification → CPU exhaustion/crash. Fixed abeb78c (break + disconnect on first KZG failure; core/txpool/validation.go + eth/fetcher/tx_fetcher.go)","name":"malformed-kzg-proof-mismatch-dos","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'malformed-kzg-proof-mismatch-dos'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Malformed Protocol Message Crash","external_references":[{"id":"CVE-2020-26264","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26264"},{"id":"CVE-2021-41173","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41173"},{"id":"CVE-2021-43668","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43668"},{"id":"CVE-2023-42805","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-42805"},{"id":"CVE-2023-46239","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46239"},{"id":"CVE-2024-35202","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35202"},{"id":"CVE-2024-45311","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45311"},{"id":"CVE-2025-24883","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24883"},{"id":"CVE-2026-32314","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32314"},{"id":"CVE-2026-32605","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32605"},{"id":"CVE-2026-40092","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40092"},{"id":"GHSA-hg58-rf2h-6rr7","kind":"ghsa","url":"https://github.com/advisories/GHSA-hg58-rf2h-6rr7"},{"id":"GHSA-hrhf-2vcr-ghch","kind":"ghsa","url":"https://github.com/advisories/GHSA-hrhf-2vcr-ghch"},{"id":"GHSA-p7mv-53f2-4cwj","kind":"ghsa","url":"https://github.com/advisories/GHSA-p7mv-53f2-4cwj"},{"id":"GHPR-Conflux-Chain-conflux-rust-3497","kind":"vendor-advisory"},{"id":"GHPR-Conflux-Chain-conflux-rust-3503","kind":"vendor-advisory"},{"id":"GHPR-Conflux-Chain-conflux-rust-3509","kind":"vendor-advisory"},{"id":"GHPR-Conflux-Chain-conflux-rust-3535","kind":"vendor-advisory"},{"id":"GHPR-XRPLF-clio-3149","kind":"vendor-advisory"},{"id":"GHPR-erigontech-erigon-21560","kind":"vendor-advisory"},{"id":"GHPR-filecoin-project-venus-6125","kind":"vendor-advisory"},{"id":"GHPR-libp2p-rust-libp2p-6472","kind":"vendor-advisory"},{"id":"GHPR-near-nearcore-16141","kind":"vendor-advisory"},{"id":"GHPR-paritytech-polkadot-sdk-12017","kind":"vendor-advisory"},{"id":"GHREL-cometbft-cometbft-v0.39.4","kind":"vendor-advisory"},{"id":"GHREL-near-nearcore-1.36.2","kind":"vendor-advisory"},{"id":"GHREL-near-nearcore-2.13.2","kind":"vendor-advisory"},{"id":"GHREL-sigp-lighthouse-v8.2.1","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0149","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Malformed Protocol Message Crash","name":"malformed-protocol-message-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'malformed-protocol-message-crash')","status":"active"},{"classification":"pending","display_name":"Malformed SOCKS Response Infinite Loop","external_references":[{"id":"CVE-2013-10005","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-10005"}],"family":null,"first_seen":"2013-01-01","id":"NRDAX-T0150","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Malformed SOCKS Response Infinite Loop","name":"malformed-socks-response-infinite-loop","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'malformed-socks-response-infinite-loop')","status":"active"},{"classification":"pending","display_name":"Malformed Transaction Field Panic","external_references":[{"id":"CVE-2026-34202","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34202"},{"id":"CVE-2026-41584","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41584"},{"id":"GHPR-cosmos-cosmos-sdk-26627","kind":"vendor-advisory"},{"id":"GHPR-erigontech-erigon-22686","kind":"vendor-advisory"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0151","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Malformed Transaction Field Panic","name":"malformed-tx-field-panic","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'malformed-tx-field-panic')","status":"active"},{"classification":"pending","display_name":"Malformed UPnP Response Infinite Loop","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0152","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Malformed UPnP Response Infinite Loop","name":"malformed-upnp-response-infinite-loop","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'malformed-upnp-response-infinite-loop')","status":"active"},{"classification":"pending","display_name":"Mempool Computational Complexity DoS","external_references":[{"id":"GHSA-f8qm-hmm3-fv7f","kind":"ghsa","url":"https://github.com/advisories/GHSA-f8qm-hmm3-fv7f"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0153","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Mempool Computational Complexity DoS","name":"mempool-computational-complexity-dos","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'mempool-computational-complexity-dos')","status":"active"},{"classification":"pending","display_name":"Mempool Deadlock DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0154","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Mempool Deadlock DoS","name":"mempool-deadlock-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'mempool-deadlock-dos')","status":"active"},{"classification":"pending","display_name":"Mempool Flood Eviction","external_references":[{"id":"CVE-2022-23327","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23327"},{"id":"CVE-2022-23328","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23328"},{"id":"CVE-2024-55563","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55563"}],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0155","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Mempool Flood Eviction","name":"mempool-flood-eviction","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'mempool-flood-eviction')","status":"active"},{"bound_failure":"mis-scoped","classification":"curated","display_name":"Mempool Pending Eviction Flood","external_references":[],"family":"memory_amp","first_seen":"2026-07-07","id":"NRDAX-T0156","instances":[{"bundle_ref":"geth_mempool_spend_all_flood","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2022-23328","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23328"}],"fidelity":"lab","primitive_id":"geth_mempool_spend_all_flood"},{"bundle_ref":"geth_tx_future_flood","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-pvx3-gm3c-gmpr","kind":"ghsa","url":"https://github.com/advisories/GHSA-pvx3-gm3c-gmpr"}],"fidelity":"lab","primitive_id":"geth_tx_future_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2022-23328 (go-ethereum, CVSS 7.5, all versions <1.10.13): an attacker node sends 5120 PENDING high-gas-price txns from ONE account that each fully spend the account's FULL BALANCE, in one eth Transactions (0x02→0x12) message. The high gas price purges the victim's pending mempool, and the 5120 same-account spend-all txns then occupy the pool → new txns can't enter → DoS. Sibling of CVE-2022-23327 (future-nonce flood) but a distinct pending-set spend-all vector. Fixed geth 1.10.13.","name":"mempool-pending-eviction-flood","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'mempool-pending-eviction-flood'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Mempool Sender Spoofing Resource Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0157","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Mempool Sender Spoofing Resource Exhaustion","name":"mempool-sender-spoofing-resource-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'mempool-sender-spoofing-resource-exhaustion')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3016.001","name":"Cryptographic Protocol Analysis","url":"https://aadapt.mitre.org/techniques/ADT3016.001"},"display_name":"Merkle Proof Forgery","external_references":[],"family":null,"first_seen":"2017-01-01","id":"NRDAX-T0158","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Merkle Proof Forgery","name":"merkle-proof-forgery","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'merkle-proof-forgery')","status":"active"},{"classification":"pending","display_name":"Merkle Trie Memory Leak","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0159","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Merkle Trie Memory Leak","name":"merkle-trie-memory-leak","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'merkle-trie-memory-leak')","status":"active"},{"classification":"pending","display_name":"Message Field Integer Overflow OOM","external_references":[{"id":"CVE-2024-32972","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32972"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0160","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Message Field Integer Overflow OOM","name":"message-field-integer-overflow-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'message-field-integer-overflow-oom')","status":"active"},{"classification":"pending","display_name":"Metric Collection Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0161","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Metric Collection Panic Crash","name":"metric-collection-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'metric-collection-panic-crash')","status":"active"},{"classification":"pending","display_name":"Metrics Endpoint Resource Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0162","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Metrics Endpoint Resource Exhaustion","name":"metrics-endpoint-resource-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'metrics-endpoint-resource-exhaustion')","status":"active"},{"classification":"pending","display_name":"Mining Pool Auth Bypass","external_references":[],"family":null,"first_seen":"2018-01-01","id":"NRDAX-T0163","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Mining Pool Auth Bypass","name":"mining-pool-auth-bypass","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'mining-pool-auth-bypass')","status":"active"},{"classification":"pending","display_name":"Missing Crypto Provider Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0164","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Missing Crypto Provider Panic Crash","name":"missing-crypto-provider-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'missing-crypto-provider-panic-crash')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Missing Zero-Guard Divide-By-Zero Halt","external_references":[{"id":"GHSA-x5vx-95h7-rv4p","kind":"ghsa","url":"https://github.com/advisories/GHSA-x5vx-95h7-rv4p"}],"family":"fault_termination","first_seen":"2026-07-07","id":"NRDAX-T0165","instances":[{"bundle_ref":"cosmos_group_divzero_halt","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-x5vx-95h7-rv4p","kind":"ghsa","url":"https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-x5vx-95h7-rv4p"}],"fidelity":"lab","primitive_id":"cosmos_group_divzero_halt"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"GHSA-x5vx-95h7-rv4p (cosmos-sdk <=0.47.15/<=0.50.11): x/group PercentageDecisionPolicy.Allow does yesCount.Quo(totalPower) with no totalPower==0 guard; a proposal on a group whose weight is driven to 0 → division-by-zero panic during FinalizeBlock → CONSENSUS FAILURE / chain halt","name":"missing-zero-guard-divide-by-zero-halt","producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'missing-zero-guard-divide-by-zero-halt'","status":"active","surface":"consensus-ingest"},{"bound_failure":"no-bound","classification":"curated","display_name":"Move Verifier Fixpoint CPU Exhaustion","external_references":[],"family":"compute_amp","first_seen":"2026-07-02","id":"NRDAX-T0166","instances":[{"bundle_ref":"sui_verifier_hamsterwheel","chain":"sui","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://medium.com/certik-skyfall/the-hamsterwheel-an-in-depth-exploration-of-a-novel-attack-vector-on-the-sui-blockchain-522f80623bc7","kind":"vendor-advisory","url":"https://medium.com/certik-skyfall/the-hamsterwheel-an-in-depth-exploration-of-a-novel-attack-vector-on-the-sui-blockchain-522f80623bc7"}],"fidelity":"lab","primitive_id":"sui_verifier_hamsterwheel"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CertiK Skyfall HamsterWheel: crafted-CFG Move module defeats id_leak_verifier fixpoint → infinite re-analysis → CPU halt","name":"move-verifier-fixpoint-cpu-exhaustion","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'move-verifier-fixpoint-cpu-exhaustion'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Nested Execution State Corruption","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0167","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Nested Execution State Corruption","name":"nested-execution-state-corruption","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'nested-execution-state-corruption')","status":"active"},{"classification":"pending","display_name":"Network Partition Consensus Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0168","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Network Partition Consensus Panic Crash","name":"network-partition-consensus-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'network-partition-consensus-panic-crash')","status":"active"},{"classification":"pending","display_name":"Network Reconnaissance Scanning","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0169","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Network Reconnaissance Scanning","name":"network-reconnaissance-scanning","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'network-reconnaissance-scanning')","status":"active"},{"classification":"pending","display_name":"Network-Triggered Runtime DoS","external_references":[{"id":"CVE-2026-3635","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3635"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0170","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Network-Triggered Runtime DoS","name":"network-triggered-runtime-dos","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'network-triggered-runtime-dos')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Nil Node Dereference Panic","external_references":[{"id":"GHPR-erigontech-erigon-22649","kind":"vendor-advisory"},{"id":"GHPR-erigontech-erigon-22745","kind":"vendor-advisory"},{"id":"GHPR-erigontech-erigon-22859","kind":"vendor-advisory"},{"id":"GHPR-erigontech-erigon-22892","kind":"vendor-advisory"}],"family":"fault_termination","first_seen":"2026-07-02","id":"NRDAX-T0171","instances":[{"bundle_ref":"geth_les_getproofsv2_dos","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2020-26264","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26264"}],"fidelity":"lab","primitive_id":"geth_les_getproofsv2_dos"},{"bundle_ref":"geth_snap_trienode_dos","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-59hh-656j-3p7v","kind":"ghsa","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-59hh-656j-3p7v"}],"fidelity":"lab","primitive_id":"geth_snap_trienode_dos"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2020-26264: a crafted LES GetProofsV2 storage-proof request (non-empty AccKey for a non-existent account) dereferences a nil account trie in the les server's GetProofsV2 handler → panic/crash (geth <1.9.25). Delivered after a real LES Status handshake to a synced --light.serve node; a patched server serves it safely (ProofsV2 reply) — the malicious request reaches the exact vulnerable handler.","name":"nil-node-dereference-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'nil-node-dereference-panic'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Nil Reference Panic Crash","external_references":[{"id":"GHPR-MystenLabs-sui-27377","kind":"vendor-advisory"},{"id":"GHPR-cosmos-cosmos-sdk-26527","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0172","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Nil Reference Panic Crash","name":"nil-reference-panic-crash","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'nil-reference-panic-crash')","status":"active"},{"classification":"pending","display_name":"Nil Response Consensus Engine Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0173","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Nil Response Consensus Engine Panic","name":"nil-response-consensus-engine-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'nil-response-consensus-engine-panic')","status":"active"},{"classification":"pending","display_name":"Non-Exploitable Cryptographic Defect","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0174","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Non-Exploitable Cryptographic Defect","name":"non-exploitable-cryptographic-defect","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'non-exploitable-cryptographic-defect')","status":"active"},{"classification":"pending","display_name":"Nonce Sequencing Proposal Degradation","external_references":[{"id":"GHSA-2557-x9mg-76w8","kind":"ghsa","url":"https://github.com/advisories/GHSA-2557-x9mg-76w8"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0175","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Nonce Sequencing Proposal Degradation","name":"nonce-sequencing-proposal-degradation","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'nonce-sequencing-proposal-degradation')","status":"active"},{"classification":"pending","display_name":"Nondeterministic Execution Consensus Split","external_references":[{"id":"CVE-2021-41135","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41135"}],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0176","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Nondeterministic Execution Consensus Split","name":"nondeterministic-execution-consensus-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'nondeterministic-execution-consensus-split')","status":"active"},{"classification":"pending","display_name":"Notification Handle Drop CPU Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0177","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Notification Handle Drop CPU Exhaustion","name":"notification-handle-drop-cpu-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'notification-handle-drop-cpu-exhaustion')","status":"active"},{"classification":"pending","display_name":"Null-Deref Crash via Crafted Input","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0178","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Null-Deref Crash via Crafted Input","name":"null-deref-crash-crafted-input","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'null-deref-crash-crafted-input')","status":"active"},{"classification":"pending","display_name":"Numeric Field Parsing Memory Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0179","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Numeric Field Parsing Memory Exhaustion","name":"numeric-field-parsing-memory-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'numeric-field-parsing-memory-exhaustion')","status":"active"},{"classification":"pending","display_name":"OIDC Identity Verification Bypass","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0180","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"OIDC Identity Verification Bypass","name":"oidc-identity-verification-bypass","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'oidc-identity-verification-bypass')","status":"active"},{"classification":"pending","display_name":"Onion Message Parsing OOM","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0181","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Onion Message Parsing OOM","name":"onion-message-parsing-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'onion-message-parsing-oom')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Optimistic ACK Congestion Window Manipulation","external_references":[],"family":"response_amp","first_seen":"2026-07-10","id":"NRDAX-T0182","instances":[{"bundle_ref":"quic_optimistic_ack_cwnd_growth","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-4820","kind":"cve","url":"https://github.com/cloudflare/quiche/security/advisories/GHSA-2v9p-3p3h-w56j"}],"fidelity":"lab","primitive_id":"quic_optimistic_ack_cwnd_growth"},{"bundle_ref":"quiche_ack_never_sent_cwnd","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"quiche_ack_never_sent_cwnd"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"quiche optimistic-ACK congestion-window growth (CVE-2025-4820): a QUIC peer completes a handshake, initiates a congestion-controlled transfer toward itself, then sends ACK frames (type 0x02 / 0x03) acknowledging packet-number ranges AHEAD of what the sender has actually sent — pacing the artificial ACKs so the server sees a very low RTT and grows its CWND without bound, admitting more bytes in flight than the path supports (availability / bandwidth amplification). CVSS 3.1 = 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). Affected quiche < 0.24.4; fixed 0.24.4. public-cve-replication — wire signature only (loopback mock plays the sender; this driver plays the attacker receiver emitting the optimistic/forward ACKs). The CWND-growth impact is a property of the vulnerable congestion controller, recorded here as advisory facts, not reproduced.","name":"optimistic-ack-congestion-window-manipulation","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'optimistic-ack-congestion-window-manipulation'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Orphan Transaction Processing DoS","external_references":[{"id":"CVE-2024-52914","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52914"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0183","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Orphan Transaction Processing DoS","name":"orphan-tx-processing-dos","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'orphan-tx-processing-dos')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Orphan Tx Resolution CPU Amplification","external_references":[],"family":"compute_amp","first_seen":"2026-07-01","id":"NRDAX-T0184","instances":[{"bundle_ref":"btc_orphan_cpu","chain":"litecoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/07/03/disclose-orphan-dos/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/07/03/disclose-orphan-dos/"}],"fidelity":"lab","primitive_id":"btc_orphan_cpu"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-52914: orphan-tx re-resolution O(outputs × 100 orphans) of expensive txs → multi-hour CPU stall","name":"orphan-tx-resolution-cpu-amplification","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'orphan-tx-resolution-cpu-amplification'","status":"active","surface":"consensus-ingest"},{"bound_failure":"no-bound","classification":"curated","display_name":"Out-Of-Order Stream Reassembly OOM","external_references":[],"family":"memory_amp","first_seen":"2026-07-10","id":"NRDAX-T0185","instances":[{"bundle_ref":"quinn_gap_fragment_reassembly_oom","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-4w2j-m93h-cj5j","kind":"ghsa","url":"https://github.com/advisories/GHSA-4w2j-m93h-cj5j"}],"fidelity":"lab","primitive_id":"quinn_gap_fragment_reassembly_oom"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"quinn-proto out-of-order stream reassembly memory exhaustion (GHSA-4w2j-m93h-cj5j / RUSTSEC-2026-0185, CVSS 7.5 AV:N/AC:L/PR:N/UI:N/A:H, CWE-770; affected quinn-proto < 0.11.15, fixed 0.11.15). An unauthenticated remote peer floods one QUIC connection with small STREAM frames at escalating non-contiguous offsets and never sends offset 0, so the receiver's `Assembler` buffers every gapped fragment as a distinct un-coalescible entry that is never deliverable -> the reassembly buffer's per-fragment overhead grows unbounded (memory exhaustion / DoS). PUBLIC-CVE REPLICATION captured here as the attack wire signature only (loopback UDP mock; no real quinn endpoint stood up); the mock_retained_* counters are a wire-side proxy for the pinned receiver memory.","name":"out-of-order-stream-reassembly-oom","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'out-of-order-stream-reassembly-oom'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Oversized Block Execution Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0186","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Oversized Block Execution Panic Crash","name":"oversized-block-execution-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'oversized-block-execution-panic-crash')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Oversized Block Response Flood","external_references":[],"family":"memory_amp","first_seen":"2026-07-04","id":"NRDAX-T0187","instances":[{"bundle_ref":"cometbft_blocksync_flood","chain":"cosmos","discovery_origin":"original-research","external_references":[{"id":"https://github.com/cometbft/cometbft/blob/v0.38.22/consensus/reactor.go","kind":"vendor-advisory","url":"https://github.com/cometbft/cometbft/blob/v0.38.22/consensus/reactor.go"}],"fidelity":"lab","primitive_id":"cometbft_blocksync_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CometBFT BlocksyncChannel(0x40) oversized BlockResponse (up to 9000 CommitSigs, ~900KB): the Block decode + ValidateBasic at https://github.com/cometbft/cometbft/blob/v0.38.22/blocksync/reactor.go is the wedge. NullRabbit-original measurement.","name":"oversized-block-response-flood","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'oversized-block-response-flood'","status":"active","surface":"consensus-ingest"},{"bound_failure":"no-bound","classification":"curated","display_name":"Oversized Control-Message Array CPU Burn","external_references":[{"id":"CVE-2026-49866","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49866"},{"id":"GHPR-Conflux-Chain-conflux-rust-3539","kind":"vendor-advisory"}],"family":"compute_amp","first_seen":"2026-01-01","id":"NRDAX-T0188","instances":[{"bundle_ref":"gossipsub_ihave_iwant_flood","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-49866","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49866"}],"fidelity":"lab","primitive_id":"gossipsub_ihave_iwant_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2026-49866: gossipsub oversized IHAVE/IWANT control-message arrays (huge messageID lists) → per-ID processing → CPU DoS","name":"oversized-control-message-array-cpu-burn","producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'oversized-control-message-array-cpu-burn'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Oversized Field Buffer Overflow","external_references":[{"id":"GHPR-Conflux-Chain-conflux-rust-3560","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0189","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Oversized Field Buffer Overflow","name":"oversized-field-buffer-overflow","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'oversized-field-buffer-overflow')","status":"active"},{"classification":"pending","display_name":"Oversized Hex String Parsing CPU Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0190","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Oversized Hex String Parsing CPU Exhaustion","name":"oversized-hex-string-parsing-cpu-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'oversized-hex-string-parsing-cpu-exhaustion')","status":"active"},{"classification":"pending","display_name":"Oversized Script Validation Bypass","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0191","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Oversized Script Validation Bypass","name":"oversized-script-validation-bypass","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'oversized-script-validation-bypass')","status":"active"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"Oversized Transaction Block-Fill","dual_with":"compute_amp","external_references":[],"family":"memory_amp","first_seen":"2024-01-01","id":"NRDAX-T0192","instances":[{"bundle_ref":"zcash_sapling_woodchip_tx_flood","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2019-11636","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11636"}],"fidelity":"lab","primitive_id":"zcash_sapling_woodchip_tx_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2019-11636 (Zcash 'Sapling Wood-Chipper'): Zcash 2.x raised the max transaction size from 100 KB to the full block size after Sapling, letting an attacker cheaply build block-filling shielded txs (fee 0.0001 ZEC/tx; ~0.0576 ZEC/day fills all ~576 daily blocks) and flood them onto the P2P network so no real transaction can be mined — a Slowloris-style asymmetric DoS on the whole chain. Fixed by reverting the max-tx-size cap to 100 KB (~10-40x cost). Modelled here as the P2P tx/inv flood wire signature; per-tx shielded-output count scaled down for capture.","name":"oversized-transaction-block-fill","producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'oversized-transaction-block-fill'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"P2P Layer Memory Leak OOM","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0193","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"P2P Layer Memory Leak OOM","name":"p2p-memory-leak-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'p2p-memory-leak-oom')","status":"active"},{"classification":"pending","display_name":"P2P Message Race Condition Crash","external_references":[{"id":"CVE-2024-32985","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32985"},{"id":"GHPR-ava-labs-avalanchego-5688","kind":"vendor-advisory"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0194","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"P2P Message Race Condition Crash","name":"p2p-message-race-condition-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'p2p-message-race-condition-crash')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Path Challenge Response Memory Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-10","id":"NRDAX-T0195","instances":[{"bundle_ref":"quic_go_path_challenge_flood","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2023-49295","kind":"cve","url":"https://github.com/quic-go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf"}],"fidelity":"lab","primitive_id":"quic_go_path_challenge_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"quic-go QUIC path-validation memory exhaustion (CVE-2023-49295): flood of QUIC v1 short-header (1-RTT) packets each carrying PATH_CHALLENGE frame(s) (type 0x1a + 8B challenge data). Each PATH_CHALLENGE obliges the receiver to enqueue a PATH_RESPONSE (type 0x1b); the attacker keeps that queue from draining by collapsing the congestion window (selective ACK) and skewing the RTT estimate, so the queue of un-sendable responses grows without bound -> memory exhaustion. The 'distributed' posture additionally sources the flood from many CHANGING (spoofed) loopback addresses — each a new path that itself triggers path validation (the connection-migration angle of the same CVE). A loopback mock cannot complete a real TLS 1.3 handshake or negotiate real congestion state, so the load-bearing wire artefacts modelled are the PATH_CHALLENGE frame type, the flood density, and the changing-source-address path fan (not real QUIC keys / cwnd). public-cve-replication — replicated wire signature, not a NullRabbit measurement. Affected quic-go v0.40.0, <= v0.39.3, <= v0.38.1, <= v0.37.6; fixed v0.40.1, v0.39.4, v0.38.2, v0.37.7; severity Moderate; reported by marten-seemann (2024-01-10). Analysis: https://seemann.io/posts/2023-12-18-exploiting-quics-path-validation/. https://github.com/quic-go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf","name":"path-challenge-response-memory-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'path-challenge-response-memory-exhaustion'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Path Migration Challenge Queue Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-10","id":"NRDAX-T0196","instances":[{"bundle_ref":"quiche_path_challenge_queue","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2023-6193","kind":"cve","url":"https://github.com/cloudflare/quiche/security/advisories/GHSA-w3vp-jw9m-f9pm"}],"fidelity":"lab","primitive_id":"quiche_path_challenge_queue"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"quiche QUIC PATH_CHALLENGE unbounded-queue flood (CVE-2023-6193): flood of QUIC 1-RTT short-header packets on one DCID arriving from CHANGING source paths (rotating loopback 4-tuples = QUIC connection migration), each carrying a PATH_CHALLENGE frame (type 0x1a) with fresh 8-byte challenge data. The recipient must echo each as a PATH_RESPONSE (type 0x1b) but, cwnd-restricted, drains slower than challenges arrive, so quiche's pending path-validation queue grows without bound. Real CVE is post-handshake 1-RTT frames; a loopback mock cannot complete a real TLS 1.3 handshake, so the queue-growth wire signature is modelled on the QUIC short-header PATH_CHALLENGE surface (frame type 0x1a + changing source paths on a fixed DCID + ever-fresh challenge data are the load-bearing artefacts). public-cve-replication — replicated wire signature, not a NullRabbit measurement. Affected quiche 0.15.0 through 0.19.0; fixed 0.19.1; CWE-400; CVSS 3.1 5.3 (Moderate). https://github.com/cloudflare/quiche/security/advisories/GHSA-w3vp-jw9m-f9pm","name":"path-migration-challenge-queue-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'path-migration-challenge-queue-exhaustion'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Payload Window Overflow Memory Exhaustion","external_references":[{"id":"GHPR-dfinity-ic-10547","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0197","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Payload Window Overflow Memory Exhaustion","name":"payload-window-overflow-memory-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'payload-window-overflow-memory-exhaustion')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Peer List Sort CPU Amplification","external_references":[],"family":"compute_amp","first_seen":"2026-07-07","id":"NRDAX-T0198","instances":[{"bundle_ref":"cardano_peershare_sort_cpu","chain":"cardano","discovery_origin":"original-research","external_references":[{"id":"https://github.com/IntersectMBO/ouroboros-network/blob/master/ouroboros-network/lib/Ouroboros/Network/PeerSharing.hs","kind":"vendor-advisory","url":"https://github.com/IntersectMBO/ouroboros-network/blob/master/ouroboros-network/lib/Ouroboros/Network/PeerSharing.hs"}],"fidelity":"lab","primitive_id":"cardano_peershare_sort_cpu"},{"bundle_ref":"conflux_hello_protocols_on2_dos","chain":"conflux","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/Conflux-Chain/conflux-rust/pull/3539","kind":"vendor-advisory","url":"https://github.com/Conflux-Chain/conflux-rust/pull/3539"}],"fidelity":"lab","primitive_id":"conflux_hello_protocols_on2_dos"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"Cardano PeerSharing MsgShareRequest O(N log N) sort CPU amp: sortBy+hashWithSalt over the ~3000-peer known set per request (~170 us), no idle timeout (Codec.hs:160), no per-peer rate limit. One post-handshake connection flooding MsgShareRequest pins ~10-20% of a core; multi-attacker linear. NullRabbit measurement; chains/cardano/findings/H_CARDANO_4_PEERSHARING.","name":"peer-list-sort-cpu-amplification","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'peer-list-sort-cpu-amplification'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Peer-Record Flood OOM","external_references":[{"id":"CVE-2023-40583","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40583"},{"id":"CVE-2026-35405","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35405"},{"id":"GHREL-libp2p-go-libp2p-v0.49.0","kind":"vendor-advisory"}],"family":"memory_amp","first_seen":"2023-01-01","id":"NRDAX-T0199","instances":[{"bundle_ref":"libp2p_signed_peer_record_flood","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-gcq9-qqwx-rgj3","kind":"ghsa","url":"https://github.com/advisories/GHSA-gcq9-qqwx-rgj3"}],"fidelity":"lab","primitive_id":"libp2p_signed_peer_record_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2023-40583: unchecked signed peer-record flood (peer-exchange) → go-libp2p peerstore OOM","name":"peer-record-flood-oom","producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'peer-record-flood-oom'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Peer Record Signature Bypass Impersonation","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0200","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Peer Record Signature Bypass Impersonation","name":"peer-record-signature-bypass-impersonation","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'peer-record-signature-bypass-impersonation')","status":"active"},{"classification":"pending","display_name":"Peer Reputation Demotion Race Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0201","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Peer Reputation Demotion Race Crash","name":"peer-reputation-demotion-race-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'peer-reputation-demotion-race-crash')","status":"active"},{"classification":"pending","display_name":"Peer Timestamp Skew Manipulation","external_references":[],"family":null,"first_seen":"2026-07-08","id":"NRDAX-T0202","instances":[{"bundle_ref":"timejacking_peer_time_skew","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md","kind":"vendor-advisory","url":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md"}],"fidelity":"lab","primitive_id":"timejacking_peer_time_skew"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"Timejacking (SlowMist Blockchain Common Vulnerability List; Culubas 2011): N peers advertise a version.timestamp skewed ~+70min (inside the AddTimeData ±70min acceptance window) → each peer's derived time-offset drags the node's median network-adjusted time → block-time (nTime/MTP) validation clock drift → stale-tip / block-rejection isolation. SlowMist gap class; no CVE.","name":"peer-timestamp-skew-manipulation","out_of_scope":true,"producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'peer-timestamp-skew-manipulation'","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Ping Flood Pending Frame OOM","external_references":[],"family":"memory_amp","first_seen":"2026-07-11","id":"NRDAX-T0203","instances":[{"bundle_ref":"yamux_ping_flood_pending_frames_oom","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-3999-5ffv-wp2r","kind":"ghsa","url":"https://github.com/libp2p/rust-yamux/security/advisories/GHSA-3999-5ffv-wp2r"}],"fidelity":"lab","primitive_id":"yamux_ping_flood_pending_frames_oom"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-32984 (GHSA-3999-5ffv-wp2r): rust-yamux (0.13.0 .. <0.13.2) buffers frames-to-send in an unbounded `pending_frames` VecDeque. A remote peer floods Ping frames (each enqueues a Pong reply) and/or opens streams while stalling its own TCP receive window (never sending WindowUpdate), so the victim's outbound frame queue cannot drain and grows without bound → remote memory exhaustion (fixed in 0.13.2, which bounds the queue).","name":"ping-flood-pending-frame-oom","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'ping-flood-pending-frame-oom'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Pre-Handshake Buffer Reservation Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0204","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Pre-Handshake Buffer Reservation Exhaustion","name":"pre-handshake-buffer-reservation-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'pre-handshake-buffer-reservation-exhaustion')","status":"active"},{"bound_failure":"late","classification":"curated","display_name":"Pre-Handshake Crypto CPU Burn","external_references":[],"family":"compute_amp","first_seen":"2022-01-01","id":"NRDAX-T0205","instances":[{"bundle_ref":"btc_bip324_prehandshake_ecdh_cpu","chain":"bitcoin","discovery_origin":"original-research","external_references":[{"id":"https://github.com/bitcoin/bitcoin/blob/master/src/bip324.cpp","kind":"vendor-advisory","url":"https://github.com/bitcoin/bitcoin/blob/master/src/bip324.cpp"}],"fidelity":"lab","primitive_id":"btc_bip324_prehandshake_ecdh_cpu"},{"bundle_ref":"casper_p521_preauth_verify_burn","chain":"casper","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"casper_p521_preauth_verify_burn"},{"bundle_ref":"cfx_ecies_preauth_ecdh_burn","chain":"conflux","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"cfx_ecies_preauth_ecdh_burn"},{"bundle_ref":"cometbft_mconn_handshake_burn","chain":"cosmos","discovery_origin":"original-research","external_references":[{"id":"cometbft-secretconnection-preauth-handshake-cpu-burn","kind":"nr-brief","title":"How CometBFT's SecretConnection handshake spends CPU before authenticating the peer","url":"https://nullrabbit.ai/research/cometbft-secretconnection-preauth-handshake-cpu-burn"},{"id":"https://github.com/cometbft/cometbft/blob/v0.38.22/p2p/conn/secret_connection.go","kind":"vendor-advisory","url":"https://github.com/cometbft/cometbft/blob/v0.38.22/p2p/conn/secret_connection.go"}],"fidelity":"lab","primitive_id":"cometbft_mconn_handshake_burn"},{"bundle_ref":"icon_goloop_preauth_ecdh_burn","chain":"icon","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"icon_goloop_preauth_ecdh_burn"},{"bundle_ref":"go_libp2p_oversized_rsa_key_cpu_burn","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-876p-8259-xjgg","kind":"ghsa","url":"https://github.com/libp2p/go-libp2p/security/advisories/GHSA-876p-8259-xjgg"}],"fidelity":"lab","primitive_id":"go_libp2p_oversized_rsa_key_cpu_burn"},{"bundle_ref":"heimdall_mconn_handshake_burn","chain":"polygon-pos","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"heimdall_mconn_handshake_burn"},{"bundle_ref":"qtum_bip324_prehandshake_ecdh_cpu","chain":"qtum","discovery_origin":"original-research","external_references":[{"id":"qtum-bip324-preauth-ecdh-cpu-dos","kind":"nr-brief","title":"Qtum BIP-324 Pre-Authentication ECDH CPU Exhaustion","url":"https://nullrabbit.ai/research/qtum-bip324-preauth-ecdh-cpu-dos"},{"id":"https://github.com/qtumproject/qtum","kind":"vendor-advisory","url":"https://github.com/qtumproject/qtum — src/net.h:95 DEFAULT_V2_TRANSPORT{true} (BIP-324 v2 on by default), src/net.cpp:1140-1147 inbound accept + src/bip324.cpp:41-64 pre-auth ellswift ECDH + HKDF-SHA256 key derivation BEFORE any auth/allowlist/rate-limit; mainnet P2P port 3888; BIP-324 salt string 'qtum_v2_shared_secret' (only salt/network-magic/port diverge from Bitcoin Core)."}],"fidelity":"lab","primitive_id":"qtum_bip324_prehandshake_ecdh_cpu"},{"bundle_ref":"rippled_overlay_handshake_ecdsa_burn","chain":"xrp","discovery_origin":"original-research","external_references":[{"id":"https://github.com/XRPLF/rippled","kind":"vendor-advisory","url":"https://github.com/XRPLF/rippled (overlay peer handshake: Handshake.cpp:318 verifyDigest -> PublicKey.cpp:222-267 secp256k1_ecdsa_verify; per-IP Resource::Consumer at OverlayImpl.cpp:235)"}],"fidelity":"lab","primitive_id":"rippled_overlay_handshake_ecdsa_burn"}],"lineage":{"deployments":9,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":9,"upper_bound":9},"mechanism":"Bitcoin Core BIP-324 v2 transport pre-auth CPU burn: the 64-byte inbound ellswift key triggers secp256k1 ellswift ECDH + HKDF-SHA256 BEFORE any auth/rate-limit; only the soft 125-inbound cap gates, accept path single-threaded. Churn of 64-byte-key connections pins a core. Measured HIGH on Bitcoin Core (55x p50/256x p99 honest-peer latency at 4 IPs) + Qtum; default-on since Core 27.0. NullRabbit measurement; chains/bitcoin/findings/BTC_V0_BIP324_PREHANDSHAKE_CPU.","name":"pre-handshake-crypto-cpu-burn","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'pre-handshake-crypto-cpu-burn'","status":"active","surface":"p2p-gossip"},{"bound_failure":"late","classification":"curated","display_name":"Pre-Handshake Packet Flood","external_references":[],"family":"compute_amp","first_seen":"2026-07-01","id":"NRDAX-T0206","instances":[{"bundle_ref":"geth_rlpx_auth_flood","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://notes.ethereum.org/gDWKW5RtSym02t2aGYkmSQ","kind":"vendor-advisory","url":"https://notes.ethereum.org/gDWKW5RtSym02t2aGYkmSQ"}],"fidelity":"lab","primitive_id":"geth_rlpx_auth_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"EL-2026-06 (EF public-disclosure): RLPx pre-auth packet flood → CPU/bandwidth exhaustion","name":"pre-handshake-packet-flood","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'pre-handshake-packet-flood'","status":"active","surface":"p2p-gossip"},{"bound_failure":"late","classification":"curated","display_name":"Pre-Verify Gossip Flood","external_references":[],"family":"compute_amp","first_seen":"2026-07-04","id":"NRDAX-T0207","instances":[{"bundle_ref":"cometbft_proposal_flood","chain":"cosmos","discovery_origin":"original-research","external_references":[{"id":"https://github.com/cometbft/cometbft/blob/v0.38.22/consensus/reactor.go","kind":"vendor-advisory","url":"https://github.com/cometbft/cometbft/blob/v0.38.22/consensus/reactor.go"}],"fidelity":"lab","primitive_id":"cometbft_proposal_flood"},{"bundle_ref":"cometbft_vote_flood","chain":"cosmos","discovery_origin":"original-research","external_references":[{"id":"https://github.com/cometbft/cometbft/blob/v0.38.22/consensus/reactor.go","kind":"vendor-advisory","url":"https://github.com/cometbft/cometbft/blob/v0.38.22/consensus/reactor.go"}],"fidelity":"lab","primitive_id":"cometbft_vote_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CometBFT consensus DataChannel(0x21) ProposalMessage flood: valid-shape Proposal passes ValidateBasic but the RLock+queue path runs before deferred sig-verify — the N1.4 family HEAD (vote-flood + blocksync-flood are its siblings). NullRabbit-original consensus-reactor measurement.","name":"pre-verify-gossip-flood","producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'pre-verify-gossip-flood'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Precompile Cryptographic Miscomputation","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0208","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Precompile Cryptographic Miscomputation","name":"precompile-cryptographic-miscomputation","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'precompile-cryptographic-miscomputation')","status":"active"},{"classification":"pending","display_name":"Predicate Verification Liveness DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0209","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Predicate Verification Liveness DoS","name":"predicate-verification-liveness-dos","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'predicate-verification-liveness-dos')","status":"active"},{"classification":"pending","display_name":"Premature Disconnect Request Handling Crash","external_references":[{"id":"CVE-2026-41585","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41585"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0210","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Premature Disconnect Request Handling Crash","name":"premature-disconnect-request-handling-crash","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'premature-disconnect-request-handling-crash')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Premature Processing Index-Out-Of-Range Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-07","id":"NRDAX-T0211","instances":[{"bundle_ref":"cometbft_voteext_panic","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-p7mv-53f2-4cwj","kind":"ghsa","url":"https://github.com/cometbft/cometbft/security/advisories/GHSA-p7mv-53f2-4cwj"}],"fidelity":"lab","primitive_id":"cometbft_voteext_panic"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"GHSA-p7mv-53f2-4cwj (ASA-2024-011): a Precommit with a non-nil BlockID + an attached vote extension is handled BEFORE the ValidatorIndex is verified → out-of-range ValidatorIndex → index-out-of-range panic on the ValidatorSet lookup (CometBFT >=0.38, fixed v0.38.15).","name":"premature-processing-index-out-of-range-panic","producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'premature-processing-index-out-of-range-panic'","status":"active","surface":"consensus-ingest"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012","name":"Exploit Smart Contract Implementation","url":"https://aadapt.mitre.org/techniques/ADT3012"},"display_name":"Proof Verification Bypass","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0212","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Proof Verification Bypass","name":"proof-verification-bypass","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'proof-verification-bypass')","status":"active"},{"classification":"pending","display_name":"Protocol Message CPU Burn","external_references":[{"id":"CVE-2026-22868","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22868"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0213","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Protocol Message CPU Burn","name":"protocol-message-cpu-burn","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'protocol-message-cpu-burn')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Protocol Message Flood Unbounded Goroutine","dual_with":"memory_amp","external_references":[{"id":"CVE-2023-40591","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40591"}],"family":"connection_exhaustion","first_seen":"2023-01-01","id":"NRDAX-T0214","instances":[{"bundle_ref":"geth_devp2p_ping_flood","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-ppjg-v974-84cm","kind":"ghsa","url":"https://github.com/ethereum/go-ethereum/security/advisories/GHSA-ppjg-v974-84cm"}],"fidelity":"lab","primitive_id":"geth_devp2p_ping_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2023-40591: post-Hello devp2p PING (0x02) flood → unbounded goroutines → OOM (geth 1.10.0-1.12.0)","name":"protocol-message-flood-unbounded-goroutine","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'protocol-message-flood-unbounded-goroutine'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Quic 0-RTT Race Memory Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0215","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Quic 0-RTT Race Memory Exhaustion","name":"quic-0rtt-race-memory-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-0rtt-race-memory-exhaustion')","status":"active"},{"classification":"pending","display_name":"QUIC Accept Error Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0216","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Accept Error Panic Crash","name":"quic-accept-error-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-accept-error-panic-crash')","status":"active"},{"classification":"pending","display_name":"QUIC Amplification Limit Bypass","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0217","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Amplification Limit Bypass","name":"quic-amplification-token-bypass","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-amplification-token-bypass')","status":"active"},{"classification":"pending","display_name":"Quic Chunks Drop Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0218","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Quic Chunks Drop Panic Crash","name":"quic-chunks-drop-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-chunks-drop-panic-crash')","status":"active"},{"classification":"pending","display_name":"Quic Client Hello Fragmentation Panic","external_references":[{"id":"GHPR-quinn-rs-quinn-2020","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0219","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Quic Client Hello Fragmentation Panic","name":"quic-client-hello-fragmentation-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-client-hello-fragmentation-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Close Frame Parsing Panic","external_references":[{"id":"GHPR-cloudflare-quiche-1341","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0220","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Close Frame Parsing Panic","name":"quic-close-frame-parsing-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-close-frame-parsing-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Congestion Control Manipulation","external_references":[{"id":"CVE-2025-4820","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4820"},{"id":"CVE-2025-4821","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4821"},{"id":"GHPR-quinn-rs-quinn-2749","kind":"vendor-advisory"}],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0221","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Congestion Control Manipulation","name":"quic-congestion-control-manipulation","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-congestion-control-manipulation')","status":"active"},{"classification":"pending","display_name":"QUIC Connection ID Exhaustion","external_references":[{"id":"CVE-2024-1410","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1410"},{"id":"CVE-2024-22189","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22189"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0222","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Connection ID Exhaustion","name":"quic-connection-id-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-connection-id-exhaustion')","status":"active"},{"classification":"pending","display_name":"QUIC Connection ID Retirement Infinite Loop","external_references":[{"id":"CVE-2025-7054","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-7054"}],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0223","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Connection ID Retirement Infinite Loop","name":"quic-connection-id-retirement-infinite-loop","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-connection-id-retirement-infinite-loop')","status":"active"},{"classification":"pending","display_name":"QUIC Connection Migration Duplicate-ID Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0224","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Connection Migration Duplicate-ID Crash","name":"quic-connection-migration-duplicate-id-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-connection-migration-duplicate-id-crash')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"QUIC Control Frame Flood","external_references":[{"id":"GHPR-quic-go-quic-go-4369","kind":"vendor-advisory"}],"family":"connection_exhaustion","first_seen":"2026-07-11","id":"NRDAX-T0225","instances":[{"bundle_ref":"s2n_quic_stream_limit_exhaustion","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-475v-pq2g-fp9g","kind":"ghsa","url":"https://github.com/aws/s2n-quic/security/advisories/GHSA-475v-pq2g-fp9g"}],"fidelity":"lab","primitive_id":"s2n_quic_stream_limit_exhaustion"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"s2n-quic stream-limit exhaustion (GHSA-475v-pq2g-fp9g): pre-patch `RemoteInitiated::on_close_stream` directly bumped `max_streams_sync` with NO rate limiting, so every close of a remote-initiated stream immediately re-grants stream credit (and makes s2n-quic emit a MAX_STREAMS frame). A peer that rapidly opens-and-closes remote-initiated streams (STREAM open+FIN then RESET_STREAM) while signalling STREAMS_BLOCKED to pull the limit up drives uncontrolled stream-controller churn / limit-sync traffic — 'unnecessary resource utilization when peers open streams beyond advertised limits' (CWE-400). No workaround; fixed in s2n-quic v1.31.0 by adding an RTT-based TokenBucket in RemoteInitiated to throttle the limit increase. Severity Low. PUBLIC-CVE REPLICATION — wire signature only (loopback UDP mock, no s2n-quic server stood up).","name":"quic-control-frame-flood","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'quic-control-frame-flood'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"QUIC Crypto Frame Flood","external_references":[{"id":"CVE-2024-1765","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1765"},{"id":"CVE-2026-10740","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10740"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0226","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Crypto Frame Flood","name":"quic-crypto-frame-flood","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-crypto-frame-flood')","status":"active"},{"classification":"pending","display_name":"QUIC Datagram Fragmentation Panic","external_references":[{"id":"GHSA-qh5x-rfwf-rvfv","kind":"ghsa","url":"https://github.com/advisories/GHSA-qh5x-rfwf-rvfv"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0227","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Datagram Fragmentation Panic","name":"quic-datagram-fragmentation-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-datagram-fragmentation-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Decryption Overflow Crash","external_references":[{"id":"GHPR-cloudflare-quiche-1154","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0228","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Decryption Overflow Crash","name":"quic-decryption-overflow-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-decryption-overflow-crash')","status":"active"},{"classification":"pending","display_name":"QUIC Early Data Processing Disclosure","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0229","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Early Data Processing Disclosure","name":"quic-early-data-processing-disclosure","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-early-data-processing-disclosure')","status":"active"},{"classification":"pending","display_name":"QUIC Empty Header Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0230","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Empty Header Panic","name":"quic-empty-header-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-empty-header-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Handshake State Confusion Crash","external_references":[{"id":"CVE-2026-61544","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61544"}],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0231","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Handshake State Confusion Crash","name":"quic-handshake-state-confusion-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-handshake-state-confusion-crash')","status":"active"},{"classification":"pending","display_name":"QUIC/HTTP3 Header Memory Exhaustion","external_references":[{"id":"CVE-2026-44892","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44892"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0232","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC/HTTP3 Header Memory Exhaustion","name":"quic-http3-header-memory-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-http3-header-memory-exhaustion')","status":"active"},{"classification":"pending","display_name":"Quic Http3 Nil Pointer Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0233","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Quic Http3 Nil Pointer Crash","name":"quic-http3-nil-pointer-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-http3-nil-pointer-crash')","status":"active"},{"classification":"pending","display_name":"QUIC Invalid Length Field Panic","external_references":[{"id":"GHPR-cloudflare-quiche-918","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0234","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Invalid Length Field Panic","name":"quic-invalid-length-field-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-invalid-length-field-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Malformed Packet Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0235","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Malformed Packet Crash","name":"quic-malformed-packet-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-malformed-packet-crash')","status":"active"},{"classification":"pending","display_name":"Quic Packet Loss Calculation Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0236","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Quic Packet Loss Calculation Panic","name":"quic-packet-loss-calculation-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-packet-loss-calculation-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Packet Processing Infinite Loop","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0237","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Packet Processing Infinite Loop","name":"quic-packet-processing-infinite-loop","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-packet-processing-infinite-loop')","status":"active"},{"classification":"pending","display_name":"QUIC Path Challenge Flood","external_references":[{"id":"CVE-2023-49295","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49295"},{"id":"CVE-2023-6193","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6193"}],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0238","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Path Challenge Flood","name":"quic-path-challenge-flood","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-path-challenge-flood')","status":"active"},{"classification":"pending","display_name":"QUIC Path Probe Nil-Pointer Crash","external_references":[{"id":"CVE-2025-29785","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29785"}],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0239","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Path Probe Nil-Pointer Crash","name":"quic-path-probe-nil-pointer-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-path-probe-nil-pointer-crash')","status":"active"},{"classification":"pending","display_name":"QUIC Post-Close Packet Processing Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0240","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Post-Close Packet Processing Crash","name":"quic-post-close-packet-processing-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-post-close-packet-processing-crash')","status":"active"},{"classification":"pending","display_name":"QUIC PTO Timer Overflow Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0241","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC PTO Timer Overflow Crash","name":"quic-pto-timer-overflow-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-pto-timer-overflow-crash')","status":"active"},{"classification":"pending","display_name":"QUIC Socket Queue Spin CPU Burn","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0242","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Socket Queue Spin CPU Burn","name":"quic-socket-queue-spin-cpu-burn","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-socket-queue-spin-cpu-burn')","status":"active"},{"classification":"pending","display_name":"Quic Transport Parameter Overflow Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0243","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Quic Transport Parameter Overflow Panic","name":"quic-transport-parameter-overflow-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-transport-parameter-overflow-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Unauthenticated Close Frame Disruption","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0244","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Unauthenticated Close Frame Disruption","name":"quic-unauthenticated-close-frame-disruption","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-unauthenticated-close-frame-disruption')","status":"active"},{"classification":"pending","display_name":"QUIC Varint Parsing Panic","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0245","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Varint Parsing Panic","name":"quic-varint-parsing-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-varint-parsing-panic')","status":"active"},{"bound_failure":"mis-scoped","classification":"curated","display_name":"Rate-Limit Key Confusion","external_references":[],"family":"connection_exhaustion","first_seen":"2026-07-09","id":"NRDAX-T0246","instances":[{"bundle_ref":"ic_ingress_pool_quota_miskey","chain":"ic","discovery_origin":"original-research","external_references":[{"id":"https://github.com/dfinity/ic","kind":"vendor-advisory","url":"https://github.com/dfinity/ic — ingress-pool per-NodeId quota mis-key: HTTP-arriving ingress is inserted with node_id = self.node_id (the carrier replica's OWN NodeId) at rs/http_endpoints/public/src/call.rs:391 (self.node_id set call.rs:104), not the signing principal; the per-peer quota exceeds_limit() then gates one SHARED bucket (rs/artifact_pool/src/ingress_pool.rs:226-232, prod caps ingress_pool_max_count=10000 / ingress_pool_max_bytes=100000000 in rs/ic_os/config/tool/templates/ic.json5.template:49-50), and RemoveFromUnvalidated (rs/ingress_manager/src/ingress_handler.rs:60-76) purges ALL unvalidated ingress for that peer. The IC team's own stale TODO acknowledges the mis-key: rs/interfaces/src/ingress_pool.rs:22-25."}],"fidelity":"lab","primitive_id":"ic_ingress_pool_quota_miskey"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"IC ingress-pool per-NodeId quota mis-key (IC_N1_INGRESS_POOL_QUOTA_MISKEY): every HTTP-arriving ingress message buckets under the carrier replica's own NodeId instead of the signing principal (call.rs:391), so a single shared per-NodeId quota gates ALL public HTTP ingress. Submitting 10001 small signed HTTP ingress POSTs trips exceeds_limit (measured 0.04s at production caps 10000 / 100 MB); the handler's RemoveFromUnvalidated then purges 100% of legit unvalidated HTTP ingress on that replica at the next on_state_change (~200ms). PUBLIC reach; ~50k signed-ingress/s keeps a replica wiped; ~40 MB total bandwidth pins a 40-replica subnet. NullRabbit measurement; chains/ic/findings/IC_N1_INGRESS_POOL_QUOTA_MISKEY.","name":"rate-limit-key-confusion","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'rate-limit-key-confusion'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Recursive Callback Stack Overflow Crash","external_references":[{"id":"GHREL-paritytech-polkadot-sdk-polkadot-stable2509-8","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0247","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Recursive Callback Stack Overflow Crash","name":"recursive-callback-stack-overflow-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'recursive-callback-stack-overflow-crash')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Recursive Filter Expression CPU Blowup","external_references":[],"family":"compute_amp","first_seen":"2026-07-03","id":"NRDAX-T0248","instances":[{"bundle_ref":"iota_s1_widefilter_subscribe_cpu","chain":"iota","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"iota_s1_widefilter_subscribe_cpu"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"IOTA_S1_EVENTFILTER_EXPONENTIAL: iotax_subscribeEvent depth-D balanced Or-tree filter → exponential CPU","name":"recursive-filter-expression-cpu-blowup","producer_family":"subscription_cpu_amp","provenance_note":"imported from nr_registry cluster 'recursive-filter-expression-cpu-blowup'","status":"active","surface":"rpc-api"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Recursive Message Deserialisation Stack Overflow","dual_with":"compute_amp","external_references":[],"family":"fault_termination","first_seen":"2026-07-01","id":"NRDAX-T0249","instances":[{"bundle_ref":"cosmos_protobuf_nest_bomb","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-8wcc-m6j2-qxvm","kind":"ghsa","url":"https://github.com/cosmos/cosmos-sdk/security/advisories/GHSA-8wcc-m6j2-qxvm"}],"fidelity":"lab","primitive_id":"cosmos_protobuf_nest_bomb"},{"bundle_ref":"sui_move_recursion","chain":"sui","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2023-36184","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36184"}],"fidelity":"lab","primitive_id":"sui_move_recursion"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"GHSA-8wcc-m6j2-qxvm (ASA-2024-0012/0013): deeply-nested protobuf Any → TxDecoder/UnpackAny stack-overflow / exponential CPU+mem in CheckTx (pre-validation)","name":"recursive-message-deserialization-stack-overflow","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'recursive-message-deserialization-stack-overflow'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Regex Schema Validation ReDoS","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0250","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Regex Schema Validation ReDoS","name":"regex-schema-validation-redos","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'regex-schema-validation-redos')","status":"active"},{"classification":"pending","display_name":"Reorg Batch Size Overflow Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0251","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Reorg Batch Size Overflow Crash","name":"reorg-batch-size-overflow-crash","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'reorg-batch-size-overflow-crash')","status":"active"},{"classification":"pending","display_name":"Reorg-Triggered Block Request Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0252","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Reorg-Triggered Block Request Crash","name":"reorg-triggered-block-request-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'reorg-triggered-block-request-crash')","status":"active"},{"classification":"pending","display_name":"Reorg Unfiltered Tx Crash Loop","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0253","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Reorg Unfiltered Tx Crash Loop","name":"reorg-unfiltered-tx-crash-loop","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'reorg-unfiltered-tx-crash-loop')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Repair Protocol Legacy Request Stall","dual_with":"connection_exhaustion","external_references":[],"family":"compute_amp","first_seen":"2026-07-09","id":"NRDAX-T0254","instances":[{"bundle_ref":"solana_repair_protocol_dos","chain":"solana","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/solana-labs/solana/releases/tag/v1.1.16","kind":"vendor-advisory","url":"https://github.com/solana-labs/solana/releases/tag/v1.1.16 — release note \"Avoid possible repair orphan DoS\"; fix PR https://github.com/solana-labs/solana/pull/10290 (\"Fix run_orphan DOS\", merged 2020-05-28), core/src/serve_repair.rs."}],"fidelity":"lab","primitive_id":"solana_repair_protocol_dos"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"Solana repair-protocol orphan DoS (solana-labs/solana v1.1.16, PR #10290): a legacy no-nonce RepairProtocol::Orphan(ContactInfo, slot) request for a slot > UNLOCK_NONCE_SLOT makes the serving node's serve_repair.rs::run_orphan loop through ALL slot metas in the blockstore building responses, 'effectively DOSing repair'. A tiny unauthenticated UDP orphan request over the serve_repair port thus commits the target to blockstore-proportional CPU (small request -> disproportionate server CPU, compute_amp). Fixed by breaking the loop when repair_response_packet returns None. Public release-note security fix, no CVE -> source_class = public-cve-replication.","name":"repair-protocol-legacy-request-stall","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'repair-protocol-legacy-request-stall'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Transaction Replay Auth Bypass","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0255","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Transaction Replay Auth Bypass","name":"replay-auth-bypass","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'replay-auth-bypass')","status":"active"},{"classification":"pending","display_name":"Replay Status Handling Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0256","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Replay Status Handling Panic","name":"replay-status-handling-panic","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'replay-status-handling-panic')","status":"active"},{"classification":"pending","display_name":"Rogue-Key Aggregate Signature Forgery","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0257","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Rogue-Key Aggregate Signature Forgery","name":"rogue-key-aggregate-signature-forgery","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'rogue-key-aggregate-signature-forgery')","status":"active"},{"classification":"pending","display_name":"RPC Arbitrary File Write","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0258","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"RPC Arbitrary File Write","name":"rpc-arbitrary-file-write","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'rpc-arbitrary-file-write')","status":"active"},{"classification":"pending","display_name":"RPC Integer Overflow Memory Corruption","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0259","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"RPC Integer Overflow Memory Corruption","name":"rpc-integer-overflow-memory-corruption","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'rpc-integer-overflow-memory-corruption')","status":"active"},{"classification":"pending","display_name":"RPC Parameter Validation Defect","external_references":[{"id":"GHPR-filecoin-project-lotus-13672","kind":"vendor-advisory"}],"family":null,"first_seen":"2018-01-01","id":"NRDAX-T0260","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"RPC Parameter Validation Defect","name":"rpc-parameter-validation-defect","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'rpc-parameter-validation-defect')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"RPC Request Flood","dual_with":"compute_amp","external_references":[],"family":"connection_exhaustion","first_seen":"2026-06-30","id":"NRDAX-T0261","instances":[{"bundle_ref":"eth_getblock_flood","chain":"ethereum","discovery_origin":"original-research","external_references":[{"id":"https://geth.ethereum.org/docs/interacting-with-geth/rpc","kind":"vendor-advisory","url":"https://geth.ethereum.org/docs/interacting-with-geth/rpc"}],"fidelity":"lab","primitive_id":"eth_getblock_flood"},{"bundle_ref":"sol_rpc_request_flood","chain":"solana","discovery_origin":"original-research","external_references":[{"id":"https://solana.com/news/9-14-network-outage-initial-overview","kind":"vendor-advisory","url":"https://solana.com/news/9-14-network-outage-initial-overview"}],"fidelity":"lab","primitive_id":"sol_rpc_request_flood"},{"bundle_ref":"sui_h02_state_sync_flood","chain":"sui","discovery_origin":"original-research","external_references":[{"id":"https://github.com/MystenLabs/sui/blob/main/crates/sui-network/src/state_sync/builder.rs","kind":"vendor-advisory","url":"https://github.com/MystenLabs/sui/blob/main/crates/sui-network/src/state_sync/builder.rs"}],"fidelity":"lab","primitive_id":"sui_h02_state_sync_flood"}],"lineage":{"deployments":3,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"eth RPC request-flood (full-tx block fetch sustained at high rate)","name":"rpc-request-flood","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'rpc-request-flood'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"RPC Request Memory Leak","external_references":[{"id":"GHPR-erigontech-erigon-22699","kind":"vendor-advisory"},{"id":"GHPR-erigontech-erigon-22700","kind":"vendor-advisory"},{"id":"GHREL-erigontech-erigon-v3.5.4","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0262","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"RPC Request Memory Leak","name":"rpc-request-memory-leak","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'rpc-request-memory-leak')","status":"active"},{"classification":"pending","display_name":"RPC Serialization Deadlock","external_references":[],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0263","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"RPC Serialization Deadlock","name":"rpc-serialization-deadlock","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'rpc-serialization-deadlock')","status":"active"},{"classification":"pending","display_name":"Scope Permission Bypass Unauthorized Write","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0264","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Scope Permission Bypass Unauthorized Write","name":"scope-permission-bypass-unauthorized-write","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'scope-permission-bypass-unauthorized-write')","status":"active"},{"classification":"pending","display_name":"Secret Key Validation Missing","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0265","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Secret Key Validation Missing","name":"secret-key-validation-missing","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'secret-key-validation-missing')","status":"active"},{"classification":"pending","display_name":"Shred Replay Processing DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0266","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Shred Replay Processing DoS","name":"shred-replay-processing-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'shred-replay-processing-dos')","status":"active"},{"classification":"pending","display_name":"Signature Malleability Consensus Manipulation","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0267","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Signature Malleability Consensus Manipulation","name":"signature-malleability-consensus-manipulation","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'signature-malleability-consensus-manipulation')","status":"active"},{"classification":"pending","display_name":"Signature Recovery CPU Burn","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0268","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Signature Recovery CPU Burn","name":"signature-recovery-cpu-burn","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'signature-recovery-cpu-burn')","status":"active"},{"classification":"pending","display_name":"Signature Verification Bypass","external_references":[{"id":"CVE-2019-15545","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15545"}],"family":null,"first_seen":"2019-01-01","id":"NRDAX-T0269","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Signature Verification Bypass","name":"signature-verification-bypass","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'signature-verification-bypass')","status":"active"},{"classification":"pending","display_name":"Signature Verification OOB Read","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0270","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Signature Verification OOB Read","name":"signature-verification-oob-read","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'signature-verification-oob-read')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3007","name":"Exploit Consensus Logic","url":"https://aadapt.mitre.org/techniques/ADT3007"},"display_name":"Signer Double-Sign Prevention Gap","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0271","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Signer Double-Sign Prevention Gap","name":"signer-double-sign-prevention-gap","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'signer-double-sign-prevention-gap')","status":"active"},{"classification":"pending","display_name":"Signer Index Overflow Crash","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0272","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Signer Index Overflow Crash","name":"signer-index-overflow-crash","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'signer-index-overflow-crash')","status":"active"},{"classification":"pending","display_name":"Signer Mismatch Bypass","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0273","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Signer Mismatch Bypass","name":"signer-mismatch-bypass","out_of_scope":true,"producer_family":"bridge","provenance_note":"known-but-not-reproduced coverage gap (technique 'signer-mismatch-bypass')","status":"active"},{"classification":"pending","display_name":"Sigop Undercount Consensus Split","external_references":[{"id":"GHSA-qvwc-hc2r-82qv","kind":"ghsa","url":"https://github.com/advisories/GHSA-qvwc-hc2r-82qv"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0274","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Sigop Undercount Consensus Split","name":"sigop-undercount-consensus-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'sigop-undercount-consensus-split')","status":"active"},{"classification":"pending","display_name":"Single-Peer Block-Discovery Stall","external_references":[{"id":"CVE-2024-52922","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52922"},{"id":"CVE-2026-44499","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44499"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0275","instances":[{"bundle_ref":"btc_cmpctblock_stall","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/11/05/cb-stall-hindering-propagation/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/11/05/cb-stall-hindering-propagation/"}],"fidelity":"lab","primitive_id":"btc_cmpctblock_stall"},{"bundle_ref":"zebra_block_discovery_dos","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-44499","kind":"cve","url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-h9hm-m2xj-4rq9"}],"fidelity":"lab","primitive_id":"zebra_block_discovery_dos"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2024-52922: cmpctblock announce then stall (never answer getblocktxn) → ~10min delayed propagation","name":"single-peer-block-discovery-stall","out_of_scope":true,"producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'single-peer-block-discovery-stall'","status":"active"},{"classification":"pending","display_name":"Slashing Implementation Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0276","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Slashing Implementation Crash","name":"slashing-implementation-crash","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'slashing-implementation-crash')","status":"active"},{"classification":"pending","display_name":"Snapshot Chunk Oversized OOM","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0277","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Snapshot Chunk Oversized OOM","name":"snapshot-chunk-oversized-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'snapshot-chunk-oversized-oom')","status":"active"},{"classification":"pending","display_name":"Snapshot File Parsing Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0278","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Snapshot File Parsing Crash","name":"snapshot-file-parsing-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'snapshot-file-parsing-crash')","status":"active"},{"classification":"pending","display_name":"SOCKS Proxy Remote Code Execution","external_references":[{"id":"CVE-2017-18350","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-18350"}],"family":null,"first_seen":"2017-01-01","id":"NRDAX-T0279","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"SOCKS Proxy Remote Code Execution","name":"socks-proxy-remote-code-execution","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'socks-proxy-remote-code-execution')","status":"active"},{"bound_failure":"late","classification":"curated","display_name":"Spoofed Endpoint-Proof Bypass Amplification","external_references":[],"family":"response_amp","first_seen":"2026-07-11","id":"NRDAX-T0280","instances":[{"bundle_ref":"conflux_discovery_findnode_reflection","chain":"conflux","discovery_origin":"original-research","external_references":[{"id":"https://github.com/Conflux-Chain/conflux-rust/blob/master/crates/network/src/discovery.rs#L346","kind":"vendor-advisory","url":"https://github.com/Conflux-Chain/conflux-rust/blob/master/crates/network/src/discovery.rs#L346"}],"fidelity":"lab","primitive_id":"conflux_discovery_findnode_reflection"},{"bundle_ref":"discv4_findnode_amplification","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"NethermindEth/nethermind#12211","kind":"vendor-advisory","url":"https://github.com/NethermindEth/nethermind/pull/12211"}],"fidelity":"lab","primitive_id":"discv4_findnode_amplification"},{"bundle_ref":"tron_discovery_findnode_reflection","chain":"tron","discovery_origin":"original-research","external_references":[{"id":"https://github.com/tronprotocol/libp2p/blob/master/src/main/java/org/tron/p2p/discover/protocol/kad/KadService.java#L122-L155","kind":"vendor-advisory","url":"https://github.com/tronprotocol/libp2p/blob/master/src/main/java/org/tron/p2p/discover/protocol/kad/KadService.java#L122-L155"}],"fidelity":"lab","primitive_id":"tron_discovery_findnode_reflection"}],"lineage":{"deployments":3,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"discv4 FINDNODE->NEIGHBORS reflection/amplification (NethermindEth/nethermind#12211): discv4 is Ethereum's connectionless-UDP node-discovery protocol. A ~170 B FINDNODE (packet-type 0x03) makes the node answer with a NEIGHBORS packet (type 0x04) of up to 16 node records (~8-13x larger). Pre-fix the node honoured FINDNODE without a PING/PONG endpoint proof bound to the exact UDP IP:port, so an attacker SPOOFING the victim's source IP reflects+amplifies the large NEIGHBORS replies onto the victim (DRDoS), and a FINDNODE burst starves the discovery response budget. #12211 requires endpoint-proof bonding (proof from endpoint A no longer authorizes requests to endpoint B) + splits the discovery rate-limit budget 50/50 between outbound requests and protocol responses. Wire framing is faithful (hash[32]||sig[65]||type||rlp; hash=keccak256(sig||type|| data)); a VALID secp256k1 signature is NOT required for the capture — the wire SHAPE + flood is the signature — so the 65-byte sig is synthetic. PUBLIC-FIX REPLICATION — loopback UDP mock plays the node (replies NEIGHBORS); no real Nethermind/geth discovery service stood up.","name":"spoofed-endpoint-proof-bypass-amplification","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'spoofed-endpoint-proof-bypass-amplification'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"SSH Password Authentication Exposure","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0281","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"SSH Password Authentication Exposure","name":"ssh-password-authentication-exposure","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'ssh-password-authentication-exposure')","status":"active"},{"classification":"pending","display_name":"Staking Slashing Evasion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0282","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Staking Slashing Evasion","name":"staking-slashing-evasion","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'staking-slashing-evasion')","status":"active"},{"classification":"pending","display_name":"Stale State Reuse Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0283","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Stale State Reuse Crash","name":"stale-state-reuse-crash","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'stale-state-reuse-crash')","status":"active"},{"classification":"pending","display_name":"State Archive Restore Corruption Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0284","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"State Archive Restore Corruption Crash","name":"state-archive-restore-corruption-crash","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'state-archive-restore-corruption-crash')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012","name":"Exploit Smart Contract Implementation","url":"https://aadapt.mitre.org/techniques/ADT3012"},"display_name":"State Channel Logic Flaw","external_references":[],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0285","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"State Channel Logic Flaw","name":"state-channel-logic-flaw","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'state-channel-logic-flaw')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012.006","name":"Signature Replay Attack","url":"https://aadapt.mitre.org/techniques/ADT3012.006"},"display_name":"State Channel Replay Attack","external_references":[],"family":null,"first_seen":"2023-01-01","id":"NRDAX-T0286","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"State Channel Replay Attack","name":"state-channel-replay-attack","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'state-channel-replay-attack')","status":"active"},{"classification":"pending","display_name":"State Simulation Copy Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0287","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"State Simulation Copy Panic","name":"state-simulation-copy-panic","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'state-simulation-copy-panic')","status":"active"},{"classification":"pending","display_name":"State Sync Proposer Priority Mismatch Chain Split","external_references":[{"id":"GHSA-g5xx-c4hv-9ccc","kind":"ghsa","url":"https://github.com/advisories/GHSA-g5xx-c4hv-9ccc"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0288","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"State Sync Proposer Priority Mismatch Chain Split","name":"state-sync-proposer-priority-mismatch-chain-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'state-sync-proposer-priority-mismatch-chain-split')","status":"active"},{"classification":"pending","display_name":"Stream Abort Race Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0289","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Stream Abort Race Crash","name":"stream-abort-race-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'stream-abort-race-crash')","status":"active"},{"classification":"pending","display_name":"Subscription Failure Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0290","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Subscription Failure Panic Crash","name":"subscription-failure-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'subscription-failure-panic-crash')","status":"active"},{"bound_failure":"mis-scoped","classification":"curated","display_name":"Subscription Permit Exhaustion","external_references":[],"family":"connection_exhaustion","first_seen":"2026-07-03","id":"NRDAX-T0291","instances":[{"bundle_ref":"cosmos_subscribe_perconn_multiply","chain":"cosmos","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"cosmos_subscribe_perconn_multiply"},{"bundle_ref":"sui_p01_p06_subscribe_filter_exhaustion","chain":"sui","discovery_origin":"original-research","external_references":[{"id":"https://github.com/MystenLabs/sui/blob/main/crates/sui-json-rpc/src/indexer_api.rs","kind":"vendor-advisory","url":"https://github.com/MystenLabs/sui/blob/main/crates/sui-json-rpc/src/indexer_api.rs"}],"fidelity":"lab","primitive_id":"sui_p01_p06_subscribe_filter_exhaustion"},{"bundle_ref":"sui_subscription_permit_leak","chain":"sui","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"sui_subscription_permit_leak"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"C04 (COSMOS_SUBSCRIBE_PERCONN_CAP): CometBFT rpc/core/events.go:27 caps NumClients>=MaxSubscriptionClients(100) but clientID=RemoteAddr(ip:PORT) → each TCP conn gets an independent per-client cap → subscription multiplication across many connections from one IP","name":"subscription-permit-exhaustion","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'subscription-permit-exhaustion'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Sync Height Manipulation Stall","external_references":[],"family":null,"first_seen":"2026-07-09","id":"NRDAX-T0292","instances":[{"bundle_ref":"cometbft_blocksync_height_decrease_stuck","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-24371","kind":"cve"}],"fidelity":"lab","primitive_id":"cometbft_blocksync_height_decrease_stuck"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2025-24371 (ASA-2025-001 / GHSA-22qq-3xwm-r5x4): a malicious CometBFT blocksync peer disrupts a node's ability to sync. In blocksync a peer reports its base/latest heights in a StatusResponse; the attacker advertises an inflated `latest` (the sync target) then advertises LOWER heights. The target is never recalculated downward, so the node tries to catch up to an unreachable height indefinitely → blocksync deadlock (restarted/new nodes cannot rejoin). Affected cometbft <= v0.38.16 and v1.0.0; fixed v0.38.17, v1.0.1. Wire signature: StatusResponse frames whose `latest` spikes high then steps DOWN, plus BlockRequests answered only by NoBlockResponse on the Blocksync channel 0x40.","name":"sync-height-manipulation-stall","out_of_scope":true,"producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'sync-height-manipulation-stall'","status":"active"},{"classification":"pending","display_name":"Sync Request Loop OOM","external_references":[{"id":"GHPR-ElementsProject-lightning-9272","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0293","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Sync Request Loop OOM","name":"sync-request-loop-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'sync-request-loop-oom')","status":"active"},{"classification":"pending","display_name":"Sync State Deadlock Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0294","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Sync State Deadlock Crash","name":"sync-state-deadlock-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'sync-state-deadlock-crash')","status":"active"},{"classification":"pending","display_name":"Sync-State Poisoning Via Fake Blocks","external_references":[{"id":"CVE-2024-52921","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52921"},{"id":"CVE-2025-24371","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24371"},{"id":"CVE-2026-52736","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52736"},{"id":"CVE-2026-52737","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52737"},{"id":"GHSA-r3r4-g7hq-pq4f","kind":"ghsa","url":"https://github.com/advisories/GHSA-r3r4-g7hq-pq4f"},{"id":"GHSA-rpcw-q5mr-gq35","kind":"ghsa","url":"https://github.com/advisories/GHSA-rpcw-q5mr-gq35"},{"id":"GHPR-bnb-chain-bsc-3766","kind":"vendor-advisory"},{"id":"GHPR-cometbft-cometbft-5803","kind":"vendor-advisory"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0295","instances":[{"bundle_ref":"zebra_sync_restart_poisoning","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2026-52737","kind":"cve","url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-gvjc-3w7c-92jx"}],"fidelity":"lab","primitive_id":"zebra_sync_restart_poisoning"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2026-52737 (GHSA-gvjc-3w7c-92jx): a single unauthenticated Zcash P2P peer answers the syncing node's getblocks/FindBlocks with a two-hash inv, then serves a `block` whose coinbase height is above tip+VERIFICATION_PIPELINE_DROP_LIMIT. Zebra returns AboveLookaheadHeightLimit, which lacks the peer address, so it triggers a GLOBAL sync restart (~67s mainnet penalty, cancels all in-flight downloads) instead of banning the peer. Repeating the (inv -> above-lookahead block) cycle pins the node in a perpetual restart loop — sustained sync-degradation DoS from one unauth peer. Node does not crash. Affected zebrad<=4.4.1 / zebra-consensus<=6.0.0; fixed v4.5.0/7.0.0 (failures made peer-local + peer banned).","name":"sync-state-poisoning-via-fake-blocks","out_of_scope":true,"producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'sync-state-poisoning-via-fake-blocks'","status":"active"},{"classification":"pending","display_name":"Template Injection RCE","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0296","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Template Injection RCE","name":"template-injection-rce","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'template-injection-rce')","status":"active"},{"classification":"pending","display_name":"Timejacking Via Version Message","external_references":[{"id":"SLOWMIST-TIMEJACKING","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0297","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Timejacking Via Version Message","name":"timejacking-via-version-message","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'timejacking-via-version-message')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3003","name":"Chain Reorganization","url":"https://aadapt.mitre.org/techniques/ADT3003"},"display_name":"Timestamp Integer Overflow Netsplit","external_references":[{"id":"CVE-2024-52912","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52912"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0298","instances":[{"bundle_ref":"btc_version_timestamp_overflow","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/07/03/disclose-timestamp-overflow/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/07/03/disclose-timestamp-overflow/"}],"fidelity":"lab","primitive_id":"btc_version_timestamp_overflow"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2024-52912: version nTime=INT64_MIN → abs64 overflow skews adjusted-network-time → netsplit","name":"timestamp-integer-overflow-netsplit","out_of_scope":true,"producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'timestamp-integer-overflow-netsplit'","status":"active"},{"classification":"pending","display_name":"Timestamp Validation Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0299","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Timestamp Validation Panic Crash","name":"timestamp-validation-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'timestamp-validation-panic-crash')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3027","name":"Side-Channel Attack","url":"https://aadapt.mitre.org/techniques/ADT3027"},"display_name":"Timing Side-Channel Deanonymization","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0300","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Timing Side-Channel Deanonymization","name":"timing-side-channel-deanonymization","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'timing-side-channel-deanonymization')","status":"active"},{"classification":"pending","display_name":"TLS Certificate Parsing Crash","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0301","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"TLS Certificate Parsing Crash","name":"tls-certificate-parsing-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'tls-certificate-parsing-crash')","status":"active"},{"classification":"pending","display_name":"TLS Handshake Fragmentation Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0302","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"TLS Handshake Fragmentation Panic","name":"tls-handshake-fragmentation-panic","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'tls-handshake-fragmentation-panic')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3018","name":"Intercept API Communication","url":"https://aadapt.mitre.org/techniques/ADT3018"},"display_name":"TLS Handshake MITM Injection","external_references":[{"id":"CVE-2014-0224","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0224"},{"id":"CVE-2025-61726","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61726"}],"family":null,"first_seen":"2014-01-01","id":"NRDAX-T0303","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"TLS Handshake MITM Injection","name":"tls-handshake-mitm-injection","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'tls-handshake-mitm-injection')","status":"active"},{"classification":"pending","display_name":"TLS Renegotiation Crash","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0304","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"TLS Renegotiation Crash","name":"tls-renegotiation-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'tls-renegotiation-crash')","status":"active"},{"classification":"pending","display_name":"TLS SNI mTLS Bypass","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0305","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"TLS SNI mTLS Bypass","name":"tls-sni-mtls-bypass","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'tls-sni-mtls-bypass')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3016","name":"Generate Counterfeit Tokens","url":"https://aadapt.mitre.org/techniques/ADT3016"},"display_name":"Token Supply Inflation Bug","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0306","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Token Supply Inflation Bug","name":"token-supply-inflation-bug","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'token-supply-inflation-bug')","status":"active"},{"classification":"pending","display_name":"Transaction Malleability","external_references":[],"family":null,"first_seen":"2026-07-09","id":"NRDAX-T0307","instances":[{"bundle_ref":"tx_malleability_txid_mutate","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md","kind":"vendor-advisory","url":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md"}],"fidelity":"lab","primitive_id":"tx_malleability_txid_mutate"},{"bundle_ref":"zcash_zebra_tx_cache_consensus_split","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-3vmh-33xr-9cqh","kind":"ghsa","url":"https://github.com/advisories/GHSA-3vmh-33xr-9cqh"}],"fidelity":"lab","primitive_id":"zcash_zebra_tx_cache_consensus_split"},{"bundle_ref":"zebra_block_sent_hash_poisoning","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"zebra_block_sent_hash_poisoning"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"Transaction Malleability (SlowMist Blockchain Common Vulnerability List): a tx and a malleated sibling with a byte-different scriptSig (extra OP_NOP) → different txid, identical inputs/outputs/effect; relaying both lets the mutant confirm under a new txid, breaking original-txid tracking (classic pre-SegWit malleability). SlowMist gap class; no CVE.","name":"transaction-malleability","out_of_scope":true,"producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'transaction-malleability'","status":"active"},{"classification":"pending","display_name":"Transaction History Storage Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0308","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Transaction History Storage Exhaustion","name":"tx-history-storage-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'tx-history-storage-exhaustion')","status":"active"},{"classification":"pending","display_name":"Tx History Storage Flood Disk Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0309","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Tx History Storage Flood Disk Exhaustion","name":"tx-history-storage-flood-disk-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'tx-history-storage-flood-disk-exhaustion')","status":"active"},{"classification":"pending","display_name":"Tx Malleability Non-Consensus","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0310","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Tx Malleability Non-Consensus","name":"tx-malleability-non-consensus","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'tx-malleability-non-consensus')","status":"active"},{"classification":"pending","display_name":"Transaction Relay Suppression","external_references":[{"id":"CVE-2024-52913","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52913"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0311","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Transaction Relay Suppression","name":"tx-relay-suppression","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'tx-relay-suppression')","status":"active"},{"classification":"pending","display_name":"Tx-Relay Throughput Jamming","external_references":[],"family":null,"first_seen":"2026-07-01","id":"NRDAX-T0312","instances":[{"bundle_ref":"bitcoin_tx_relay_jamming","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2024-55563","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-55563"}],"fidelity":"lab","primitive_id":"bitcoin_tx_relay_jamming"},{"bundle_ref":"btc_inv_eviction_jam","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/07/03/disclose_already_asked_for/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/07/03/disclose_already_asked_for/"}],"fidelity":"lab","primitive_id":"btc_inv_eviction_jam"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2024-55563 (Bitcoin Core <= 27.2): transaction-relay jamming via an off-chain protocol attack ('Transaction-Relay Throughput Overflow Attacks against Off-Chain Protocols'; related to CVE-2024-52913). High-overflow variant: a flood of many small higher-feerate txs + their inv announcements overflows the fee-rate-sorted forward-transaction inventory (INVENTORY_BROADCAST_MAX / CompareInvMempoolOrder), so a lower-feerate pre-signed Lightning HTLC/commitment tx is never announced (jammed) before its timelock expires -> HTLC outcome changed.","name":"tx-relay-throughput-jamming","out_of_scope":true,"producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'tx-relay-throughput-jamming'","status":"active"},{"classification":"pending","display_name":"Transaction Validation Logic Consensus Split","external_references":[{"id":"CVE-2026-34377","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34377"},{"id":"CVE-2026-41583","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41583"},{"id":"CVE-2026-44497","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44497"},{"id":"GHSA-wm9c-xvqq-5c28","kind":"ghsa","url":"https://github.com/advisories/GHSA-wm9c-xvqq-5c28"},{"id":"GHREL-jito-foundation-jito-solana-v4.2.0-beta.2-jito.1","kind":"vendor-advisory"}],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0313","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Transaction Validation Logic Consensus Split","name":"tx-validation-logic-consensus-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'tx-validation-logic-consensus-split')","status":"active"},{"classification":"pending","display_name":"TxPool Crafted Transaction Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0314","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"TxPool Crafted Transaction Crash","name":"txpool-crafted-transaction-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'txpool-crafted-transaction-crash')","status":"active"},{"classification":"pending","display_name":"TxPool Message Flood OOM","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0315","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"TxPool Message Flood OOM","name":"txpool-message-flood-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'txpool-message-flood-oom')","status":"active"},{"classification":"pending","display_name":"Unaligned Memory Access Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0316","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unaligned Memory Access Crash","name":"unaligned-memory-access-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'unaligned-memory-access-crash')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT1552","name":"Unsecured Credentials","url":"https://aadapt.mitre.org/techniques/ADT1552"},"display_name":"Unauthenticated Admin Interface Exposure","external_references":[],"family":null,"first_seen":"2018-01-01","id":"NRDAX-T0317","instances":[{"bundle_ref":"geth_rpc_unlocked_wallet_drain","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md","kind":"vendor-advisory","url":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md"}],"fidelity":"lab","primitive_id":"geth_rpc_unlocked_wallet_drain"},{"bundle_ref":"sui_h01_admin_no_auth_probe","chain":"sui","discovery_origin":"original-research","external_references":[{"id":"https://github.com/MystenLabs/sui/blob/main/crates/sui-node/src/admin.rs","kind":"vendor-advisory","url":"https://github.com/MystenLabs/sui/blob/main/crates/sui-node/src/admin.rs"}],"fidelity":"lab","primitive_id":"sui_h01_admin_no_auth_probe"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"Black Valentine (SlowMist Blockchain Common Vulnerability List): geth --http with the personal namespace exposed + an unlocked/unlockable account → remote unauthenticated personal_unlockAccount then eth_sendTransaction flood drains the wallet. No CVE.","name":"unauthenticated-admin-interface-exposure","out_of_scope":true,"producer_family":"auth_bypass","provenance_note":"imported from nr_registry cluster 'unauthenticated-admin-interface-exposure'","status":"active"},{"classification":"pending","display_name":"Unauthenticated RPC Command Execution","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0318","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unauthenticated RPC Command Execution","name":"unauthenticated-rpc-command-execution","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'unauthenticated-rpc-command-execution')","status":"active"},{"classification":"pending","display_name":"Unbounded Alert Map OOM","external_references":[{"id":"CVE-2016-10724","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10724"}],"family":null,"first_seen":"2016-01-01","id":"NRDAX-T0319","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unbounded Alert Map OOM","name":"unbounded-alert-map-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'unbounded-alert-map-oom')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Connection Flood","external_references":[{"id":"CVE-2020-5303","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-5303"}],"family":"connection_exhaustion","first_seen":"2020-01-01","id":"NRDAX-T0320","instances":[{"bundle_ref":"cosmos_p2p_conn_flood","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-v24h-pjjv-mcp6","kind":"ghsa","url":"https://github.com/tendermint/tendermint/security/advisories/GHSA-v24h-pjjv-mcp6"}],"fidelity":"lab","primitive_id":"cosmos_p2p_conn_flood"},{"bundle_ref":"geth_tcp_handshake_flood","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://reports.immunefi.com/ethereum-protocol-or-attackathon/37120-bc-insight-remote-handshake-based-tcp-30303-flooding-leads-to-an-out-of-memory-crash","kind":"vendor-advisory","url":"https://reports.immunefi.com/ethereum-protocol-or-attackathon/37120-bc-insight-remote-handshake-based-tcp-30303-flooding-leads-to-an-out-of-memory-crash"}],"fidelity":"lab","primitive_id":"geth_tcp_handshake_flood"},{"bundle_ref":"libp2p_conn_resource_exhaustion","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-f44q-634c-jvwv","kind":"ghsa","url":"https://github.com/libp2p/js-libp2p/security/advisories/GHSA-f44q-634c-jvwv"}],"fidelity":"lab","primitive_id":"libp2p_conn_resource_exhaustion"},{"bundle_ref":"monero_rpc_conn_exhaustion","chain":"monero","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-26819","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26819"}],"fidelity":"lab","primitive_id":"monero_rpc_conn_exhaustion"},{"bundle_ref":"dnsdist_doq_concurrent_conn_exhaustion","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"dnsdist_doq_concurrent_conn_exhaustion"},{"bundle_ref":"firedancer_metrics_flood_crash","chain":"solana","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/firedancer-io/firedancer/releases/tag/v0.106.11814","kind":"vendor-advisory","url":"https://github.com/firedancer-io/firedancer/releases/tag/v0.106.11814 — Firedancer v0.106.11814 (Testnet) Bug Fixes: \"Fixed an issue where a connection flood to the metrics server could crash the validator.\" Firedancer's fd_metrics tile serves Prometheus-compatible metrics over HTTP (default 127.0.0.1:7999/metrics; listen address operator-configurable / internet-exposable per the Firedancer bug-bounty guidance). A remote inbound TCP connection flood to the metrics port could crash the whole validator prior to this fix."}],"fidelity":"lab","primitive_id":"firedancer_metrics_flood_crash"},{"bundle_ref":"starknet_libp2p_noise_preauth_flood","chain":"starknet","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"starknet_libp2p_noise_preauth_flood"}],"lineage":{"deployments":7,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":7,"upper_bound":7},"mechanism":"CVE-2020-5303 (Lavender): unlimited CometBFT P2P connection requests → OOM + activeIDs-map saturation","name":"unbounded-connection-flood","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'unbounded-connection-flood'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Connection ID Storage","external_references":[],"family":"memory_amp","first_seen":"2026-07-10","id":"NRDAX-T0321","instances":[{"bundle_ref":"quic_conn_id_memory_exhaustion","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2024-22189","kind":"cve","url":"https://github.com/quic-go/quic-go/security/advisories/GHSA-c33x-xqrf-c478"}],"fidelity":"lab","primitive_id":"quic_conn_id_memory_exhaustion"},{"bundle_ref":"quiche_conn_id_retirement_unbounded","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2024-1410","kind":"cve","url":"https://github.com/advisories/GHSA-xhg9-xwch-vr7x"}],"fidelity":"lab","primitive_id":"quiche_conn_id_retirement_unbounded"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"quic-go connection-ID memory exhaustion (CVE-2024-22189, GHSA-c33x-xqrf-c478): on an established QUIC connection the attacker floods NEW_CONNECTION_ID frames (type 0x18) with an escalating 'Retire Prior To' field. Each escalation forces the peer (RFC 9000 §19.15) to retire the connection IDs below it and to queue a RETIRE_CONNECTION_ID frame per retirement. The attacker prevents the peer from ever draining that queue by collapsing its congestion window (selective ACKing) and inflating its RTT estimate, so the RETIRE_CONNECTION_ID frames accumulate unbounded → peer runs out of memory (CWE-770, no per-connection cap). No workaround; fixed in quic-go v0.42.0. PUBLIC-CVE REPLICATION — wire signature only (loopback UDP mock, no quic-go server stood up).","name":"unbounded-connection-id-storage","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unbounded-connection-id-storage'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Unbounded Deserialisation OOM","external_references":[{"id":"CVE-2026-40881","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40881"},{"id":"CVE-2026-44500","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44500"},{"id":"GHSA-8wcc-m6j2-qxvm","kind":"ghsa","url":"https://github.com/advisories/GHSA-8wcc-m6j2-qxvm"},{"id":"GHSA-qgw7-x3x7-p35x","kind":"ghsa","url":"https://github.com/advisories/GHSA-qgw7-x3x7-p35x"},{"id":"GHPR-bnb-chain-bsc-3590","kind":"vendor-advisory"},{"id":"GHPR-near-nearcore-16129","kind":"vendor-advisory"},{"id":"GHPR-near-nearcore-16131","kind":"vendor-advisory"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0322","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unbounded Deserialisation OOM","name":"unbounded-deserialisation-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'unbounded-deserialisation-oom')","status":"active"},{"classification":"pending","display_name":"Unbounded Filter Subscription Storage Exhaustion","external_references":[{"id":"GHREL-hyperledger-besu-26.7.1","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0323","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unbounded Filter Subscription Storage Exhaustion","name":"unbounded-filter-subscription-storage-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'unbounded-filter-subscription-storage-exhaustion')","status":"active"},{"classification":"pending","display_name":"Unbounded Log Range Scan Amplification","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0324","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unbounded Log Range Scan Amplification","name":"unbounded-log-range-scan-amplification","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'unbounded-log-range-scan-amplification')","status":"active"},{"classification":"pending","display_name":"Unbounded Message Loop Halt","external_references":[{"id":"GHSA-v6rw-hhgg-wc4x","kind":"ghsa","url":"https://github.com/advisories/GHSA-v6rw-hhgg-wc4x"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0325","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unbounded Message Loop Halt","name":"unbounded-message-loop-halt","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'unbounded-message-loop-halt')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Peer-Slot Sybil","external_references":[{"id":"SLOWMIST-SYBIL","kind":"vendor-advisory"}],"family":"connection_exhaustion","first_seen":"2026-07-09","id":"NRDAX-T0326","instances":[{"bundle_ref":"sybil_peer_identity_flood","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md","kind":"vendor-advisory","url":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md"}],"fidelity":"lab","primitive_id":"sybil_peer_identity_flood"},{"bundle_ref":"geth_sybil_identity_flood","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md","kind":"vendor-advisory","url":"https://github.com/slowmist/Cryptocurrency-Security-Audit-Guide/blob/main/Blockchain-Common-Vulnerability-List.md"}],"fidelity":"lab","primitive_id":"geth_sybil_identity_flood"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"Sybil (SlowMist Blockchain Common Vulnerability List): a flood of full RLPx+eth-handshake peers each with a DISTINCT node identity occupies the target's inbound peer slots and biases peer selection (eclipse precursor); accepted as full peers, unlike blank handshake floods or alien-chain pollution. SlowMist gap class; no CVE.","name":"unbounded-peer-slot-sybil","producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'unbounded-peer-slot-sybil'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Registration Storage Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-10","id":"NRDAX-T0327","instances":[{"bundle_ref":"libp2p_rendezvous_cookie_exhaustion","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-v5hw-cv9c-rpg7","kind":"ghsa","url":"https://github.com/advisories/GHSA-v5hw-cv9c-rpg7"}],"fidelity":"lab","primitive_id":"libp2p_rendezvous_cookie_exhaustion"},{"bundle_ref":"libp2p_rendezvous_namespace_oom","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-cqfx-gf56-8x59","kind":"ghsa","url":"https://github.com/advisories/GHSA-cqfx-gf56-8x59"}],"fidelity":"lab","primitive_id":"libp2p_rendezvous_namespace_oom"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2026-35457 (GHSA-v5hw-cv9c-rpg7): libp2p-rendezvous server stores DISCOVER pagination cookies in an unbounded in-memory map (Registrations::cookies) with no size cap / eviction / expiry — a flood of unauthenticated /rendezvous/1.0.0 DISCOVER requests forces one fresh Cookie + HashSet entry per request → linear memory growth → remote memory exhaustion (fixed in 0.17.1).","name":"unbounded-registration-storage-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unbounded-registration-storage-exhaustion'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Request Body Memory Exhaustion","external_references":[{"id":"GHPR-monero-project-monero-10139","kind":"vendor-advisory"}],"family":"memory_amp","first_seen":"2026-07-07","id":"NRDAX-T0328","instances":[{"bundle_ref":"cardano_submit_api_body_memory_pin","chain":"cardano","discovery_origin":"original-research","external_references":[{"id":"cardano-submit-api-unbounded-body-memory-exhaustion","kind":"nr-brief","title":"Cardano cardano-submit-api: unbounded request body → memory exhaustion","url":"https://nullrabbit.ai/research/cardano-submit-api-unbounded-body-memory-exhaustion"},{"id":"https://github.com/IntersectMBO/cardano-node/blob/master/cardano-submit-api/src/Cardano/TxSubmit/Rest/Types.hs","kind":"vendor-advisory","url":"https://github.com/IntersectMBO/cardano-node/blob/master/cardano-submit-api/src/Cardano/TxSubmit/Rest/Types.hs"}],"fidelity":"lab","primitive_id":"cardano_submit_api_body_memory_pin"},{"bundle_ref":"prysm_attester_slashing_pubkey_burn","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"prysm_attester_slashing_pubkey_burn"},{"bundle_ref":"prysm_bls_exec_change_decode_burn","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"prysm_bls_exec_change_decode_burn"},{"bundle_ref":"prysm_bls_pool_decode_burn","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"prysm_bls_pool_decode_burn"},{"bundle_ref":"reth_pooledtx_decode_memory_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[{"id":"https://github.com/paradigmxyz/reth/pull/23718","kind":"vendor-advisory","url":"https://github.com/paradigmxyz/reth/pull/23718"}],"fidelity":"lab","primitive_id":"reth_pooledtx_decode_memory_amp"},{"bundle_ref":"ic_orchestrator_cup_body_bomb","chain":"ic","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"ic_orchestrator_cup_body_bomb"},{"bundle_ref":"monero_wallet_rpc_body_size_dos","chain":"monero","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"monero_wallet_rpc_body_size_dos"}],"lineage":{"deployments":4,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":7,"upper_bound":7},"mechanism":"PRYSM_ATTESTER_SLASHING_PUBKEY_BURN (S4): POST /eth/v1/beacon/pool/attester_slashings_v2 decodes one AttesterSlashingElectra whose attesting_indices vector is capped only at the structural MaxValidatorsPerCommittee*MaxCommitteesPerSlot = 131,072 (attestation.go:259; no body cap, no rate-limit) then runs a per-index pubkey-deser/subgroup-check loop before the pairing short-circuits → 3.06 s/req cold-cache measured. NullRabbit-original on prysm HEAD; no CVE.","name":"unbounded-request-body-memory-exhaustion","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'unbounded-request-body-memory-exhaustion'","status":"active","surface":"rpc-api"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded RPC Response Amplification","external_references":[{"id":"CVE-2025-26819","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26819"},{"id":"GHPR-matter-labs-zksync-era-4860","kind":"vendor-advisory"}],"family":"response_amp","first_seen":"2025-01-01","id":"NRDAX-T0329","instances":[{"bundle_ref":"aptos_f10_modules_amp","chain":"aptos","discovery_origin":"original-research","external_references":[{"id":"https://aptos.dev/en/build/apis/fullnode-rest-api","kind":"vendor-advisory","url":"https://aptos.dev/en/build/apis/fullnode-rest-api"}],"fidelity":"lab","primitive_id":"aptos_f10_modules_amp"},{"bundle_ref":"eth_call_stateoverride_large_return_buffer_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_call_stateoverride_large_return_buffer_amp"},{"bundle_ref":"eth_createaccesslist_storagekey_cardinality_fanout_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_createaccesslist_storagekey_cardinality_fanout_amp"},{"bundle_ref":"eth_getblockreceipts_full_block_receipt_log_fanout_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_getblockreceipts_full_block_receipt_log_fanout_amp"},{"bundle_ref":"eth_getlogs_response_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[{"id":"geth-eth-getlogs-wide-range-response-amplification","kind":"nr-brief","title":"How a wide-range eth_getLogs query turns a few hundred bytes into an unbounded response on exposed go-ethereum RPC nodes","url":"https://nullrabbit.ai/research/geth-eth-getlogs-wide-range-response-amplification"},{"id":"https://geth.ethereum.org/docs/interacting-with-geth/rpc","kind":"vendor-advisory","url":"https://geth.ethereum.org/docs/interacting-with-geth/rpc"}],"fidelity":"lab","primitive_id":"eth_getlogs_response_amp"},{"bundle_ref":"eth_getlogs_wide_blockrange_full_log_return_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_getlogs_wide_blockrange_full_log_return_amp"},{"bundle_ref":"eth_simulateV1_gapblock_autofill_header_breadth_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_simulateV1_gapblock_autofill_header_breadth_amp"},{"bundle_ref":"geth_eth_receipt_flood","chain":"ethereum","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://reports.immunefi.com/ethereum-protocol-or-attackathon/37466-bc-medium-evil-client-oom-crash-fast-p2p-crash","kind":"vendor-advisory","url":"https://reports.immunefi.com/ethereum-protocol-or-attackathon/37466-bc-medium-evil-client-oom-crash-fast-p2p-crash"}],"fidelity":"lab","primitive_id":"geth_eth_receipt_flood"},{"bundle_ref":"iota_f10_grpc_batch_amp","chain":"iota","discovery_origin":"original-research","external_references":[{"id":"https://docs.iota.org/references/iota-api","kind":"vendor-advisory","url":"https://docs.iota.org/references/iota-api (gRPC LedgerService GetObjects/GetTransactions; F10 response-amp class)"}],"fidelity":"lab","primitive_id":"iota_f10_grpc_batch_amp"},{"bundle_ref":"iota_f10_multiget_amp","chain":"iota","discovery_origin":"original-research","external_references":[{"id":"https://docs.iota.org/references/iota-api/iota/method/iota_multiGetObjects","kind":"vendor-advisory","url":"https://docs.iota.org/references/iota-api/iota/method/iota_multiGetObjects"}],"fidelity":"lab","primitive_id":"iota_f10_multiget_amp"},{"bundle_ref":"SOL_F10_multi_get_accounts_amp","chain":"solana","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"SOL_F10_multi_get_accounts_amp"},{"bundle_ref":"sol_getsigs_response_amp","chain":"solana","discovery_origin":"original-research","external_references":[{"id":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md","kind":"vendor-advisory","url":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md"}],"fidelity":"lab","primitive_id":"sol_getsigs_response_amp"},{"bundle_ref":"sol_gpa_response_amp","chain":"solana","discovery_origin":"original-research","external_references":[{"id":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md","kind":"vendor-advisory","url":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md"}],"fidelity":"lab","primitive_id":"sol_gpa_response_amp"},{"bundle_ref":"sui_f10_multiget_response_amp","chain":"sui","discovery_origin":"original-research","external_references":[{"id":"https://github.com/MystenLabs/sui/blob/main/docs/content/references/sui-api.mdx","kind":"vendor-advisory","url":"https://github.com/MystenLabs/sui/blob/main/docs/content/references/sui-api.mdx"}],"fidelity":"lab","primitive_id":"sui_f10_multiget_response_amp"},{"bundle_ref":"sui_p05_multiget_txblocks_amp","chain":"sui","discovery_origin":"original-research","external_references":[{"id":"https://github.com/MystenLabs/sui/blob/main/docs/content/references/sui-api.mdx","kind":"vendor-advisory","url":"https://github.com/MystenLabs/sui/blob/main/docs/content/references/sui-api.mdx"}],"fidelity":"lab","primitive_id":"sui_p05_multiget_txblocks_amp"},{"bundle_ref":"rippled_batch_response_amp","chain":"xrp","discovery_origin":"original-research","external_references":[{"id":"https://github.com/XRPLF/rippled/blob/develop/src/xrpld/rpc/detail/ServerHandler.cpp","kind":"vendor-advisory","url":"https://github.com/XRPLF/rippled/blob/develop/src/xrpld/rpc/detail/ServerHandler.cpp"}],"fidelity":"lab","primitive_id":"rippled_batch_response_amp"},{"bundle_ref":"zcash_zebra_getaddresstxids_response_amp","chain":"zcash","discovery_origin":"original-research","external_references":[{"id":"https://zcash.github.io/rpc/getaddressutxos.html","kind":"vendor-advisory","url":"https://zcash.github.io/rpc/getaddressutxos.html (unpaginated list RPC; F10 response-amp class)"}],"fidelity":"lab","primitive_id":"zcash_zebra_getaddresstxids_response_amp"},{"bundle_ref":"zcash_zebra_getaddressutxos_response_amp","chain":"zcash","discovery_origin":"original-research","external_references":[{"id":"https://zcash.github.io/rpc/getaddressutxos.html","kind":"vendor-advisory","url":"https://zcash.github.io/rpc/getaddressutxos.html (unpaginated list RPC; F10 response-amp class)"}],"fidelity":"lab","primitive_id":"zcash_zebra_getaddressutxos_response_amp"},{"bundle_ref":"zcash_zebra_getblocktemplate_response_amp","chain":"zcash","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"zcash_zebra_getblocktemplate_response_amp"},{"bundle_ref":"zcash_zebra_getrawmempool_verbose_response_amp","chain":"zcash","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"zcash_zebra_getrawmempool_verbose_response_amp"}],"lineage":{"deployments":7,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":20,"upper_bound":20},"mechanism":"The node's JSON-RPC handler for batched account-lookup calls (e.g. getMultipleAccounts) imposes no response-size accounting or cost weighting relative to request size, only a flat cap on key count. An attacker submits a small request (~4.8KB) listing well-known large program accounts (Token/BPFLoader2/BPFLoaderUpgradeable), whose ELF/program data stubs are echoed in full, driving a single request to a ~17.8MB response (3,708x amplification) and sustained ~830MB/s egress under parallel workers. The fix-class is response-size-aware rate limiting/cost accounting on batched read RPCs (weighting by bytes returned, not just item count), not a request-count cap.","name":"unbounded-rpc-response-amplification","producer_family":"response_amp","provenance_note":"imported from nr_registry cluster 'unbounded-rpc-response-amplification'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Unbounded Signature Verification CPU Exhaustion","external_references":[{"id":"GHPR-tronprotocol-java-tron-6820","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0330","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unbounded Signature Verification CPU Exhaustion","name":"unbounded-signature-verification-cpu-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'unbounded-signature-verification-cpu-exhaustion')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Stream Backpressure OOM","dual_with":"memory_amp","external_references":[],"family":"connection_exhaustion","first_seen":"2026-07-01","id":"NRDAX-T0331","instances":[{"bundle_ref":"libp2p_stream_exhaustion","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-j7qp-mfxf-8xjw","kind":"ghsa","url":"https://github.com/advisories/GHSA-j7qp-mfxf-8xjw"}],"fidelity":"lab","primitive_id":"libp2p_stream_exhaustion"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2022-23492/CVE-2022-23486: libp2p stream/connection exhaustion (no backpressure) → OOM","name":"unbounded-stream-backpressure-oom","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'unbounded-stream-backpressure-oom'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Unbounded Stream Resource Exhaustion","external_references":[{"id":"CVE-2022-23486","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23486"},{"id":"CVE-2022-23487","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23487"},{"id":"CVE-2022-23492","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23492"},{"id":"CVE-2025-54604","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54604"},{"id":"CVE-2025-54605","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54605"},{"id":"CVE-2026-35457","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35457"},{"id":"GHPR-NethermindEth-nethermind-12345","kind":"vendor-advisory"}],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0332","instances":[{"bundle_ref":"coredns_doq_stream_slowloris","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"coredns_doq_stream_slowloris"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CoreDNS DoQ stream slowloris (CVE-2025-47950 / GHSA-cvx7-x8pj-x2gw): CoreDNS' DNS-over-QUIC server created a new goroutine for every incoming QUIC stream with NO cap on concurrent streams/goroutines (1:1 stream->goroutine). The DoQ framing (RFC 9250: 2-octet big-endian length prefix per DNS message) reads that prefix and the body with blocking io.ReadFull() calls that have NO per-stream read deadline. A remote, unauthenticated attacker opens many QUIC streams (e.g. 60 conns x 256 streams = 15,360) and sends only 1 byte on each — the first byte of the length prefix — then stalls; each io.ReadFull blocks forever waiting for the second byte, pinning a worker goroutine, and once workers are exhausted every further stream still spawns a goroutine that blocks on a worker token, so goroutine/RSS grow without bound -> OOM-kill/crash (a QUIC-native slowloris), especially in memory-constrained containers. CVSS 7.5 HIGH (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Affects `quic://`-enabled Corefiles; no workaround; fixed v1.12.2 (max_streams default 256 + bounded worker_pool_size default 1024). Fix was incomplete — regression CVE-2026-32934 / GHSA-2wpx-qpw2-g5h5, fixed v1.14.3. PUBLIC-CVE REPLICATION — wire signature only (loopback UDP mock, no CoreDNS DoQ server stood up).","name":"unbounded-stream-resource-exhaustion","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'unbounded-stream-resource-exhaustion'","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Subscription Flood","external_references":[{"id":"CVE-2026-46679","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46679"}],"family":"connection_exhaustion","first_seen":"2026-01-01","id":"NRDAX-T0333","instances":[{"bundle_ref":"iota_graphql_s1_unbounded_subs","chain":"iota","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"iota_graphql_s1_unbounded_subs"},{"bundle_ref":"gossipsub_subscribe_flood","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-4f8r-922h-2vgv","kind":"ghsa","url":"https://github.com/advisories/GHSA-4f8r-922h-2vgv"}],"fidelity":"lab","primitive_id":"gossipsub_subscribe_flood"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"NullRabbit source-traced IOTA GraphQL unbounded-subscription flood (operator-gated).","name":"unbounded-subscription-flood","producer_family":"connection_exhaustion","provenance_note":"imported from nr_registry cluster 'unbounded-subscription-flood'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Unbounded Task Spawn Resource Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0334","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unbounded Task Spawn Resource Exhaustion","name":"unbounded-task-spawn-resource-exhaustion","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'unbounded-task-spawn-resource-exhaustion')","status":"active"},{"classification":"pending","display_name":"Unchecked Inherent Manipulation","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0335","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unchecked Inherent Manipulation","name":"unchecked-inherent-manipulation","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'unchecked-inherent-manipulation')","status":"active"},{"classification":"pending","display_name":"Unchecked Memory Write Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0336","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unchecked Memory Write Panic","name":"unchecked-memory-write-panic","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'unchecked-memory-write-panic')","status":"active"},{"classification":"pending","display_name":"Unexploitable Dependency Vulnerability","external_references":[],"family":null,"first_seen":"2018-01-01","id":"NRDAX-T0337","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unexploitable Dependency Vulnerability","name":"unexploitable-dependency-vulnerability","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'unexploitable-dependency-vulnerability')","status":"active"},{"classification":"pending","display_name":"Unhandled Enum Variant Panic","external_references":[],"family":null,"first_seen":"2026-07-15","id":"NRDAX-T0338","instances":[{"bundle_ref":"quinn_unknown_frame_panic","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"quinn_unknown_frame_panic"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2023-42805 (RUSTSEC-2023-0063): quinn-proto < 0.9.5/0.10.5 panics on a QUIC frame with an UNKNOWN frame type (RFC 9000 §12.4 requires FRAME_ENCODING_ERROR, not a crash). A single packet carrying one undefined-type frame crashes the endpoint (availability DoS). Fixed by principled invalid-frame error handling (quinn PR #1667). Modelled as the unknown-frame-type wire signature. https://rustsec.org/advisories/RUSTSEC-2023-0063.html","name":"unhandled-enum-variant-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'unhandled-enum-variant-panic'","status":"active"},{"classification":"pending","display_name":"Unhandled Fork Event Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0339","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unhandled Fork Event Panic","name":"unhandled-fork-event-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'unhandled-fork-event-panic')","status":"active"},{"classification":"pending","display_name":"Unhandled Promise Rejection Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0340","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unhandled Promise Rejection Crash","name":"unhandled-promise-rejection-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'unhandled-promise-rejection-crash')","status":"active"},{"classification":"pending","display_name":"Unhandled RPC Error Panic","external_references":[{"id":"GHPR-MystenLabs-sui-26528","kind":"vendor-advisory"},{"id":"GHPR-erigontech-erigon-22623","kind":"vendor-advisory"},{"id":"GHPR-ethereum-go-ethereum-35396","kind":"vendor-advisory"},{"id":"GHPR-starkware-libs-sequencer-14412","kind":"vendor-advisory"},{"id":"GHREL-Conflux-Chain-conflux-rust-v0.3.2","kind":"vendor-advisory"},{"id":"GHREL-erigontech-erigon-v3.5.3","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0341","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unhandled RPC Error Panic","name":"unhandled-rpc-error-panic","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'unhandled-rpc-error-panic')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unindexed Account Scan CPU Amplification","external_references":[],"family":"compute_amp","first_seen":"2026-06-30","id":"NRDAX-T0342","instances":[{"bundle_ref":"sol_getblocks_enum_scan","chain":"solana","discovery_origin":"original-research","external_references":[{"id":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md","kind":"vendor-advisory","url":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md"}],"fidelity":"lab","primitive_id":"sol_getblocks_enum_scan"},{"bundle_ref":"sol_gpa_compute_scan","chain":"solana","discovery_origin":"original-research","external_references":[{"id":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md","kind":"vendor-advisory","url":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md"}],"fidelity":"lab","primitive_id":"sol_gpa_compute_scan"},{"bundle_ref":"sui_p07_getownedobjects_scan","chain":"sui","discovery_origin":"original-research","external_references":[{"id":"https://github.com/MystenLabs/sui/blob/main/crates/sui-core/src/authority.rs","kind":"vendor-advisory","url":"https://github.com/MystenLabs/sui/blob/main/crates/sui-core/src/authority.rs"}],"fidelity":"lab","primitive_id":"sui_p07_getownedobjects_scan"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"E28/SOL_P07: getProgramAccounts filter-miss CPU scan (agave rpc.rs:2235-2251)","name":"unindexed-account-scan-cpu-amplification","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'unindexed-account-scan-cpu-amplification'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Uninitialized Buffer Memory Disclosure","external_references":[{"id":"CVE-2021-45684","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-45684"}],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0343","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Uninitialized Buffer Memory Disclosure","name":"uninitialized-buffer-memory-disclosure","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'uninitialized-buffer-memory-disclosure')","status":"active"},{"classification":"pending","display_name":"Uninitialized Memory Disclosure","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0344","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Uninitialized Memory Disclosure","name":"uninitialized-memory-disclosure","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'uninitialized-memory-disclosure')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unrated GetHeaders Response Flood","external_references":[],"family":"response_amp","first_seen":"2026-07-01","id":"NRDAX-T0345","instances":[{"bundle_ref":"p2p_getheaders_drain","chain":"litecoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2023-33297","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33297"}],"fidelity":"lab","primitive_id":"p2p_getheaders_drain"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2023-33297 (drain): un-rate-limited getheaders flood → >100MB/s upload (Bitcoin/Litecoin/Dogecoin)","name":"unrated-getheaders-response-flood","producer_family":"response_amp","provenance_note":"imported from nr_registry cluster 'unrated-getheaders-response-flood'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Unresolvable Finalized Block Wedge","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0346","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unresolvable Finalized Block Wedge","name":"unresolvable-finalized-block-wedge","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'unresolvable-finalized-block-wedge')","status":"active"},{"classification":"pending","display_name":"Unsafe Deserialization Memory Corruption","external_references":[{"id":"CVE-2018-3972","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-3972"},{"id":"CVE-2021-3121","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3121"}],"family":null,"first_seen":"2018-01-01","id":"NRDAX-T0347","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unsafe Deserialization Memory Corruption","name":"unsafe-deserialization-memory-corruption","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'unsafe-deserialization-memory-corruption')","status":"active"},{"classification":"pending","display_name":"Unsafe Deserialization RCE","external_references":[{"id":"CVE-2022-42003","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42003"}],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0348","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Unsafe Deserialization RCE","name":"unsafe-deserialization-rce","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'unsafe-deserialization-rce')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unseeded Hash Collision DoS","external_references":[],"family":"compute_amp","first_seen":"2026-07-11","id":"NRDAX-T0349","instances":[{"bundle_ref":"quic_scid_collision_hash_dos","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2025-47200","kind":"cve","url":"https://www.nccgroup.com/research/technical-advisory-hash-denial-of-service-attack-in-multiple-quic-implementations/"}],"fidelity":"lab","primitive_id":"quic_scid_collision_hash_dos"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"QUIC SCID hash-collision DoS (CVE-2025-47200): a flood of QUIC v1 Initial packets whose 8-byte Source Connection IDs are crafted to COLLIDE in the server's connection-ID hash table. The server keys active connections on the peer SCID; a weak non-seeded hash (NCC names FNV, xxHash, and `hash = hash*31 + char`) lets the attacker hold a constant 5-byte SCID prefix (5c1dc011de) and vary a 3-byte counter suffix, keeping only suffixes whose full-SCID hash lands in one target bucket — so every DISTINCT SCID collides. Worst-case O(n) bucket walks (amortised O(n^2)) burn server CPU: NCC measured ~300x slowdown from 10k parallel colliding connections. Only SipHash (keyed) mitigates. PUBLIC-CVE replication of the NCC Group / Fox-IT advisory; new corpus wire family = algorithmic-complexity / hash-DoS.","name":"unseeded-hash-collision-dos","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'unseeded-hash-collision-dos'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Unsolicited Block State Poisoning","external_references":[{"id":"GHSA-382w-958v-m5jr","kind":"ghsa","url":"https://github.com/advisories/GHSA-382w-958v-m5jr"}],"family":null,"first_seen":"2026-07-01","id":"NRDAX-T0350","instances":[{"bundle_ref":"btc_mutated_block","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/10/08/disclose-mutated-blocks-hindering-propagation/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/10/08/disclose-mutated-blocks-hindering-propagation/"}],"fidelity":"lab","primitive_id":"btc_mutated_block"},{"bundle_ref":"cometbft_blocksync_malicious_peer","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-hg58-rf2h-6rr7","kind":"ghsa","url":"https://github.com/cometbft/cometbft/security/advisories/GHSA-hg58-rf2h-6rr7"}],"fidelity":"lab","primitive_id":"cometbft_blocksync_malicious_peer"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2024-52921: unrequested merkle-mismatched block erases other peers' download state → hinders propagation","name":"unsolicited-block-state-poisoning","out_of_scope":true,"producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'unsolicited-block-state-poisoning'","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unvalidated DHT Record Storage Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-10","id":"NRDAX-T0351","instances":[{"bundle_ref":"libp2p_dht_putvalue_disk_exhaustion","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-32mq-hpph-xfvr","kind":"ghsa","url":"https://github.com/advisories/GHSA-32mq-hpph-xfvr"}],"fidelity":"lab","primitive_id":"libp2p_dht_putvalue_disk_exhaustion"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2026-45783 / GHSA-32mq-hpph-xfvr: the libp2p Kademlia DHT (@libp2p/kad-dht (npm, js-libp2p), affected < 16.2.6) accepts and persists PUT_VALUE records with no effective validation, count, or byte budget. Two combined defects: (1) `verifyRecord` silently returns early for keys with fewer than 3 slash-delimited parts, so a crafted key bypasses all content validation and the record is written to the datastore anyway; (2) the RPC message loop resets its inactivity timeout after each message and imposes NO per-stream message-count limit and NO per-peer byte budget. Combined: an unauthenticated peer opens one /ipfs/kad/1.0.0 stream and floods distinct crafted PUT_VALUE records → the victim's datastore grows without bound until the host disk is exhausted and the DHT server node becomes unavailable. Server-mode DHT nodes are the default for publicly-routable addresses (IPFS/bootstrap nodes). No auth required. Fixed in 16.2.6 (rejects unrecognized keys instead of silently accepting them).","name":"unvalidated-dht-record-storage-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unvalidated-dht-record-storage-exhaustion'","status":"active","surface":"p2p-gossip"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Unvalidated Field Length Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-03","id":"NRDAX-T0352","instances":[{"bundle_ref":"quiche_0rtt_packet_len_panic","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"quiche_0rtt_packet_len_panic"},{"bundle_ref":"quiche_payload_overflow_crash","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"quiche_payload_overflow_crash"},{"bundle_ref":"sol_snapshot_oversized_datalen_indexgen_panic","chain":"solana-agave","discovery_origin":"original-research","external_references":[{"id":"agave-snapshot-appendvec-datalen-indexgen-panic","kind":"nr-brief","title":"Crashing an Agave validator during snapshot bootstrap with one oversized account length","url":"https://nullrabbit.ai/research/agave-snapshot-appendvec-datalen-indexgen-panic"},{"id":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md","kind":"vendor-advisory","url":"https://github.com/anza-xyz/agave/blob/master/SECURITY.md"}],"fidelity":"lab","primitive_id":"sol_snapshot_oversized_datalen_indexgen_panic"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"Agave snapshot AppendVec StoredMeta.data_len > MAX_PERMITTED_DATA_LENGTH (10 MiB) survives new_for_startup (sanitize skipped) -> index-gen scan_accounts QuotaExceeded -> .expect(\"must scan accounts storage\") panic; pre-hash-gate bootstrap crash. Out-of-scope per Anza SECURITY.md (maliciously-crafted-snapshots / bootstrap-config-mitigable) -> publishable. source_class=original.","name":"unvalidated-field-length-panic","producer_family":"state_import_abuse","provenance_note":"imported from nr_registry cluster 'unvalidated-field-length-panic'","status":"active","surface":"sync-state-import"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unvalidated Header Buffer OOM","external_references":[],"family":"memory_amp","first_seen":"2026-01-01","id":"NRDAX-T0353","instances":[{"bundle_ref":"btc_headers_genesis_spam","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/07/03/disclose-header-spam/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/07/03/disclose-header-spam/"}],"fidelity":"lab","primitive_id":"btc_headers_genesis_spam"},{"bundle_ref":"btc_headers_oom","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://bitcoincore.org/en/2024/09/18/disclose-headers-oom/","kind":"vendor-advisory","url":"https://bitcoincore.org/en/2024/09/18/disclose-headers-oom/"}],"fidelity":"lab","primitive_id":"btc_headers_oom"},{"bundle_ref":"conflux_newblock_header_custom_oom","chain":"conflux","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/Conflux-Chain/conflux-rust/pull/3541","kind":"vendor-advisory","url":"https://github.com/Conflux-Chain/conflux-rust/pull/3541"}],"fidelity":"lab","primitive_id":"conflux_newblock_header_custom_oom"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":3,"upper_bound":3},"mechanism":"CVE-2024-52916: difficulty-1 headers with parent=genesis → mapBlockIndex unbounded growth → memory DoS","name":"unvalidated-header-buffer-oom","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unvalidated-header-buffer-oom'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unvalidated Inventory Tracking Memory Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-01","id":"NRDAX-T0354","instances":[{"bundle_ref":"btc_invdos_flood","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://invdos.net/","kind":"vendor-advisory","url":"https://invdos.net/"}],"fidelity":"lab","primitive_id":"btc_invdos_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"CVE-2018-17145 (INVDoS): random-hash INV flood → unbounded tx-tracking memory","name":"unvalidated-inventory-tracking-memory-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unvalidated-inventory-tracking-memory-exhaustion'","status":"active","surface":"p2p-gossip"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unvalidated Relay Map Memory Exhaustion","external_references":[],"family":"memory_amp","first_seen":"2026-07-01","id":"NRDAX-T0355","instances":[{"bundle_ref":"btc_alert_flood","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2016-10724","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10724"}],"fidelity":"lab","primitive_id":"btc_alert_flood"},{"bundle_ref":"btc_tx_maprelay","chain":"bitcoin","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"CVE-2013-4627","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4627"}],"fidelity":"lab","primitive_id":"btc_tx_maprelay"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"CVE-2016-10724: pre-0.13.0 alert messages stored in an unbounded map → memory exhaustion","name":"unvalidated-relay-map-memory-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unvalidated-relay-map-memory-exhaustion'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"UPnP Gateway Event Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0356","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"UPnP Gateway Event Panic Crash","name":"upnp-gateway-event-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'upnp-gateway-event-panic-crash')","status":"active"},{"classification":"pending","display_name":"UPnP Response Buffer Overflow","external_references":[],"family":null,"first_seen":"2015-01-01","id":"NRDAX-T0357","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"UPnP Response Buffer Overflow","name":"upnp-response-buffer-overflow","producer_family":"supply-chain","provenance_note":"known-but-not-reproduced coverage gap (technique 'upnp-response-buffer-overflow')","status":"active"},{"classification":"pending","display_name":"URL Path Encoding Auth Bypass","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0358","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"URL Path Encoding Auth Bypass","name":"url-path-encoding-auth-bypass","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'url-path-encoding-auth-bypass')","status":"active"},{"classification":"pending","display_name":"Verbose Logging Triggered Crash","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0359","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Verbose Logging Triggered Crash","name":"verbose-logging-triggered-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'verbose-logging-triggered-crash')","status":"active"},{"classification":"pending","display_name":"Vesting Account Creation Front-Running","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0360","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Vesting Account Creation Front-Running","name":"vesting-account-creation-frontrun","producer_family":"governance","provenance_note":"known-but-not-reproduced coverage gap (technique 'vesting-account-creation-frontrun')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3012","name":"Exploit Smart Contract Implementation","url":"https://aadapt.mitre.org/techniques/ADT3012"},"display_name":"Vesting Logic Exploit","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0361","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Vesting Logic Exploit","name":"vesting-logic-exploit","out_of_scope":true,"producer_family":"economic-defi","provenance_note":"known-but-not-reproduced coverage gap (technique 'vesting-logic-exploit')","status":"active"},{"classification":"pending","display_name":"VM Integer Overflow Memory Corruption","external_references":[],"family":null,"first_seen":"2021-01-01","id":"NRDAX-T0362","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"VM Integer Overflow Memory Corruption","name":"vm-integer-overflow-memory-corruption","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'vm-integer-overflow-memory-corruption')","status":"active"},{"classification":"pending","display_name":"VM Resource Exhaustion OOM","external_references":[{"id":"GHSA-m3rh-cvr5-x6q4","kind":"ghsa","url":"https://github.com/advisories/GHSA-m3rh-cvr5-x6q4"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0363","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"VM Resource Exhaustion OOM","name":"vm-resource-exhaustion-oom","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'vm-resource-exhaustion-oom')","status":"active"},{"classification":"pending","display_name":"VM Stack Overflow Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0364","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"VM Stack Overflow Crash","name":"vm-stack-overflow-crash","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'vm-stack-overflow-crash')","status":"active"},{"classification":"pending","display_name":"VM Stack Underflow Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0365","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"VM Stack Underflow Panic","name":"vm-stack-underflow-panic","producer_family":"ledger-tx","provenance_note":"known-but-not-reproduced coverage gap (technique 'vm-stack-underflow-panic')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3007.001","name":"Circumvent Voting Majority Control","url":"https://aadapt.mitre.org/techniques/ADT3007.001"},"display_name":"Vote Extension Power Mutation","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0366","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Vote Extension Power Mutation","name":"vote-extension-power-mutation","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'vote-extension-power-mutation')","status":"active"},{"classification":"pending","display_name":"Vote Extension Validation Panic","external_references":[],"family":null,"first_seen":"2024-01-01","id":"NRDAX-T0367","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Vote Extension Validation Panic","name":"vote-extension-validation-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'vote-extension-validation-panic')","status":"active"},{"classification":"pending","display_name":"Vote Signature Late Verification Resource Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0368","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Vote Signature Late Verification Resource Exhaustion","name":"vote-signature-late-verification-resource-exhaustion","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'vote-signature-late-verification-resource-exhaustion')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"WebSocket Task Spawn Exhaustion","dual_with":"memory_amp","external_references":[],"family":"connection_exhaustion","first_seen":"2026-07-08","id":"NRDAX-T0369","instances":[{"bundle_ref":"sui_jsonrpsee_h4_ws_task_spawn","chain":"sui","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"sui_jsonrpsee_h4_ws_task_spawn"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"NullRabbit source-traced H4 slow-read","name":"websocket-task-spawn-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'websocket-task-spawn-exhaustion'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"WebTransport Capsule Memory Exhaustion","external_references":[{"id":"CVE-2026-57497","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57497"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0370","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"WebTransport Capsule Memory Exhaustion","name":"webtransport-capsule-memory-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'webtransport-capsule-memory-exhaustion')","status":"active"},{"classification":"pending","display_name":"WebTransport Close Handler Deadlock","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0371","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"WebTransport Close Handler Deadlock","name":"webtransport-close-handler-deadlock","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'webtransport-close-handler-deadlock')","status":"active"},{"classification":"pending","display_name":"WebTransport Message Parsing Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0372","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"WebTransport Message Parsing Crash","name":"webtransport-message-parsing-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'webtransport-message-parsing-crash')","status":"active"},{"classification":"pending","display_name":"WebTransport Stream Map Leak OOM","external_references":[],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0373","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"WebTransport Stream Map Leak OOM","name":"webtransport-stream-map-leak-oom","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'webtransport-stream-map-leak-oom')","status":"active"},{"classification":"pending","display_name":"Witness Block Parsing DoS","external_references":[],"family":null,"first_seen":"2022-01-01","id":"NRDAX-T0374","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Witness Block Parsing DoS","name":"witness-block-parsing-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'witness-block-parsing-dos')","status":"active"},{"classification":"pending","display_name":"XML Attribute Parsing Quadratic CPU Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0375","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"XML Attribute Parsing Quadratic CPU Exhaustion","name":"xml-attribute-parsing-quadratic-cpu-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'xml-attribute-parsing-quadratic-cpu-exhaustion')","status":"active"},{"classification":"pending","display_name":"XML Namespace Declaration Memory Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0376","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"XML Namespace Declaration Memory Exhaustion","name":"xml-namespace-declaration-memory-exhaustion","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'xml-namespace-declaration-memory-exhaustion')","status":"active"},{"classification":"pending","display_name":"Zero-Length Field Panic Crash","external_references":[{"id":"GHPR-erigontech-erigon-22712","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0377","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Zero-Length Field Panic Crash","name":"zero-length-field-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'zero-length-field-panic-crash')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3016.001","name":"Cryptographic Protocol Analysis","url":"https://aadapt.mitre.org/techniques/ADT3016.001"},"display_name":"ZK Proof Forgery Acceptance","external_references":[],"family":null,"first_seen":"2019-01-01","id":"NRDAX-T0378","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"ZK Proof Forgery Acceptance","name":"zk-proof-forgery-acceptance","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'zk-proof-forgery-acceptance')","status":"active"},{"classification":"pending","display_name":"ZK Verifier Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0379","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"ZK Verifier Panic Crash","name":"zk-verifier-panic-crash","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'zk-verifier-panic-crash')","status":"active"},{"classification":"pending","display_name":"zkVM Guest Memory Safety","external_references":[],"family":null,"first_seen":"2025-01-01","id":"NRDAX-T0380","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"zkVM Guest Memory Safety","name":"zkvm-guest-memory-safety","producer_family":"crypto","provenance_note":"known-but-not-reproduced coverage gap (technique 'zkvm-guest-memory-safety')","status":"active"},{"classification":"pending","display_name":"ZMQ Message Error-Handling Crash","external_references":[{"id":"GHPR-monero-project-monero-9052","kind":"vendor-advisory"}],"family":null,"first_seen":"2026-07-17","id":"NRDAX-T0381","instances":[{"bundle_ref":"monero_zmq_eagain_crash","chain":"monero","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/monero-project/monero/pull/9052","kind":"vendor-advisory","url":"https://github.com/monero-project/monero/pull/9052"}],"fidelity":"lab","primitive_id":"monero_zmq_eagain_crash"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"monero PR #9052: with ZMQ-PUB enabled the ZMQ-RPC server uses zmq_poll; an INVALID non-ZMQ message (e.g. a browser HTTP request to the ZMQ-RPC TCP port) bypasses the poll filter, reaches zmq_read which returns EAGAIN, and the unhandled spurious wakeup PERMANENTLY crashes ZMQ-RPC until restart (remote availability DoS). Fixed by handling EAGAIN. Modelled as the HTTP-to-ZMQ-port wire signature. https://github.com/monero-project/monero/pull/9052","name":"zmq-message-error-handling-crash","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'zmq-message-error-handling-crash'","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Error-Response Connection-State Leak","external_references":[],"family":"memory_amp","first_seen":"2026-07-13","id":"NRDAX-T0382","instances":[{"bundle_ref":"dnsdist_doq_error_query_mem_leak","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"dnsdist_doq_error_query_mem_leak"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"dnsdist's DoQ/DoH3 receiver allocates per-error bookkeeping state whenever it emits a self-generated FORMERR/REFUSED/SERVFAIL/NOTIMP response, and attaches that state to the QUIC connection object rather than the completed stream/query, freeing it only on full connection teardown. An attacker opens a single DoQ/DoH3 connection and streams a large run of complete, well-formed queries engineered to each trigger a local error response, causing the per-error allocations to accumulate unboundedly for as long as the connection (or its parallel siblings) stays open. The fix-class is scoping/freeing per-error bookkeeping to the query/stream lifetime instead of the connection lifetime, bounding memory growth regardless of connection duration.","name":"error-response-connection-state-leak","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'error-response-connection-state-leak'","status":"active","surface":"p2p-gossip"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"HPACK Decoded-Size Accounting Bypass","external_references":[],"family":"memory_amp","first_seen":"2026-07-13","id":"NRDAX-T0383","instances":[{"bundle_ref":"envoy_http2_hpack_cookie_amplification","chain":"http2","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"envoy_http2_hpack_cookie_amplification"},{"bundle_ref":"http2_bomb_indexed_ref_window_pin","chain":"http2","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"http2_bomb_indexed_ref_window_pin"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"Envoy's HTTP/2 HPACK decoder bounds header-block size on ENCODED bytes only, and cookie header bytes bypass the max_request_headers_kb decoded-size accounting entirely. An attacker plants one large cookie value once in the HPACK dynamic table via a literal-with-incremental-indexing field, then re-references that single entry many times per request using 1-byte indexed-header-field octets, so the wire stays tiny while Envoy materializes the full cookie value on every reference. The fix-class is bounding/accounting the DECODED header size (including cookie bytes) rather than just the encoded HPACK block, closing the asymmetric-allocation gap; without it, a few connections/streams balloon decoded-header memory past the process limit and get OOM-killed within seconds.","name":"hpack-decoded-size-accounting-bypass","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'hpack-decoded-size-accounting-bypass'","status":"active","surface":"rpc-api"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"HTTP/2 Continuation Frame Flood","external_references":[],"family":"compute_amp","first_seen":"2026-07-13","id":"NRDAX-T0384","instances":[{"bundle_ref":"http2_continuation_flood","chain":"http2","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"http2_continuation_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The HTTP/2 decoder's header-list-size guard is size-based (maxHeaderListSize - frameSize < currentSize) and never trips when each CONTINUATION frame carries zero bytes, so no count limit exists on CONTINUATION frames following an unterminated HEADERS block (END_HEADERS=0). An attacker opens a header block and streams an unbounded sequence of zero-length CONTINUATION frames on one connection, each costing only a 9-byte frame header to send. The decoder keeps parsing every frame, monopolizing a CPU thread and producing a compute-exhaustion DoS at negligible attacker bandwidth.","name":"http2-continuation-frame-flood","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'http2-continuation-frame-flood'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Invalid Block Disk Replay Exhaustion","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0385","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Invalid Block Disk Replay Exhaustion","name":"invalid-block-disk-replay-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'invalid-block-disk-replay-exhaustion')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Priority-Field Parse-Exception Leak","external_references":[],"family":"memory_amp","first_seen":"2026-07-13","id":"NRDAX-T0386","instances":[{"bundle_ref":"http2_malformed_priority_leak_flood","chain":"http2","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"http2_malformed_priority_leak_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The HTTP/2 priority parser (RFC 9218 urgency field) throws an unhandled IllegalArgumentException when given an out-of-range value (e.g. u=99), and the request-handling code path lacks a catch/cleanup for this failure, leaving the half-processed request's state permanently retained. An attacker floods the server with malformed PRIORITY_UPDATE frames or priority headers, each triggering the same uncaught-exception path, causing unbounded cumulative memory retention across requests. Effect: gradual heap growth culminating in OutOfMemoryError / DoS. The fix-class is 'catch parser exceptions and ensure per-request cleanup/dispatch on all error paths', distinguishing it from stream-count or flow-control exhaustion techniques.","name":"priority-field-parse-exception-leak","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'priority-field-parse-exception-leak'","status":"active","surface":"rpc-api"},{"bound_failure":"no-bound","classification":"curated","display_name":"QPACK Blocked-Decode Flow-Control Leak","external_references":[],"family":"memory_amp","first_seen":"2026-07-13","id":"NRDAX-T0387","instances":[{"bundle_ref":"envoy_http3_qpack_blocked_decode_leak","chain":"http3","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"envoy_http3_qpack_blocked_decode_leak"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The QPACK decoder returns QUIC stream- and connection-level flow-control credit for HEADERS bytes belonging to field sections that reference dynamic-table entries not yet inserted (Required Insert Count > inserted count), even though those bytes remain resident in the decoder's blocked-section heap buffer. An attacker sends such blocked field sections and never supplies the corresponding encoder-stream inserts, so the sections never decode or free, while continuing to send more HEADERS traffic using the wrongly-returned flow-control credit. This decouples flow-control accounting from actual buffer occupancy, letting the attacker drive unbounded heap growth in the decoder and exhaust memory/DoS the HTTP/3 stack.","name":"qpack-blocked-decode-flow-control-leak","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'qpack-blocked-decode-flow-control-leak'","status":"active","surface":"rpc-api"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unbounded Header-List-Size Default OOM","external_references":[],"family":"memory_amp","first_seen":"2026-07-13","id":"NRDAX-T0388","instances":[{"bundle_ref":"netty_http3_field_section_oom","chain":"http3","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"netty_http3_field_section_oom"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The node-side defect is an insecure default: the HTTP/3 codec's maxHeaderListSize defaults to the near-unbounded RFC 9114 ceiling ((1<<62)-1) whenever a peer omits SETTINGS_MAX_FIELD_SECTION_SIZE, instead of inheriting the safe bounded default already enforced for HTTP/1.1 and HTTP/2. An attacker simply never sends that setting, then transmits a HEADERS/QPACK block containing an enormous COUNT of distinct literal header fields; the codec keeps decoding and buffering each field with no size ceiling. The fix-class is enforcing a safe bounded default (and/or hard cap independent of peer-advertised settings) for field-section size in the HTTP/3 codec, which measurably manifests as unbounded heap growth culminating in OutOfMemoryError/process death.","name":"unbounded-header-list-size-default-oom","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unbounded-header-list-size-default-oom'","status":"active","surface":"rpc-api"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"Precompile Gas Underpricing CPU Burn","external_references":[],"family":"compute_amp","first_seen":"2026-07-14","id":"NRDAX-T0389","instances":[{"bundle_ref":"eth_call_blake2f_precompile_rounds_cpu_amp","chain":"ethereum","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"eth_call_blake2f_precompile_rounds_cpu_amp"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The BLAKE2F precompile (0x09) exposes an attacker-controlled 'rounds' field that is charged at a flat 1-gas-per-round rate but executes synchronously on the node's RPC-serving thread; because gas cost scales linearly while wall-clock compute per round is effectively free to request, a small eth_call payload (~585 bytes) can force tens of millions of compression rounds. This yields a large asymmetry between request size/cost and CPU time consumed (~405ms vs ~1ms baseline), letting a single cheap call monopolize a worker thread and degrade node responsiveness. The fix-class is bounding/metering precompile-invoked loop primitives (rounds/iteration caps, tighter gas-to-wall-time calibration, or synchronous-call time budgets) at the eth_call/precompile-dispatch layer.","name":"precompile-gas-underpricing-cpu-burn","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'precompile-gas-underpricing-cpu-burn'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"QUIC Path Event Queue Exhaustion","external_references":[{"id":"CVE-2026-12707","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12707"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0390","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Path Event Queue Exhaustion","name":"quic-path-event-queue-exhaustion","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-path-event-queue-exhaustion')","status":"active"},{"classification":"pending","display_name":"RPC Chunk Response Size Latency DoS","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0391","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"RPC Chunk Response Size Latency DoS","name":"rpc-chunk-response-size-latency-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'rpc-chunk-response-size-latency-dos')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Invalid UTF-8 Decode Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-15","id":"NRDAX-T0392","instances":[{"bundle_ref":"quiche_nonutf8_close_panic","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"quiche_nonutf8_close_panic"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The node's qlog logging path assumes the CONNECTION_CLOSE/APPLICATION_CLOSE reason-phrase field is valid UTF-8 and decodes it directly into a Rust `str` for logging, even though RFC 9000 §19.19 defines the reason phrase as opaque bytes with no UTF-8 requirement. A remote peer sends a single CLOSE frame (0x1c/0x1d) whose reason-phrase bytes are deliberately invalid UTF-8 (e.g. stray continuation bytes), triggering a decode/conversion panic in the qlog writer and crashing the victim process — a one-packet availability DoS. The fix-class is defensive/lossy decoding (or byte-safe handling) of all peer-supplied opaque protocol fields before they are passed to logging, serialization, or string-typed APIs.","name":"invalid-utf8-decode-panic","producer_family":"protocol_logic_exploit","provenance_note":"imported from nr_registry cluster 'invalid-utf8-decode-panic'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"RPC Exception Log Amplification","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0393","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"RPC Exception Log Amplification","name":"rpc-exception-log-amplification","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'rpc-exception-log-amplification')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Connection ID Retirement Infinite Loop","external_references":[],"family":"compute_amp","first_seen":"2026-07-15","id":"NRDAX-T0394","instances":[{"bundle_ref":"quiche_retire_cid_loop","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"quiche_retire_cid_loop"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The node's connection-ID retirement handler does not terminate/converge when RETIRE_CONNECTION_ID and NEW_CONNECTION_ID sequence numbers are exchanged across multiple migrated paths in a circular pattern (retiring the CID in use on path A from path B and vice versa), violating the RFC 9000 §19.16 invariant that a packet must not retire the CID it was sent on. An attacker who completes the handshake and drives path migration across ≥2 paths while crafting this circular retirement sequence triggers an unbounded loop in the retirement logic (CWE-835), pinning the victim at 100% CPU — a post-handshake remote compute-exhaustion DoS. Fix-class is bounding/validating cross-path CID retirement transitions so the state machine always reaches a valid exit, distinct from fixes that bound the retired-CID store size for single-path floods.","name":"connection-id-retirement-infinite-loop","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'connection-id-retirement-infinite-loop'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"Fork Recovery Logic Exploit","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0395","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Fork Recovery Logic Exploit","name":"fork-recovery-logic-exploit","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'fork-recovery-logic-exploit')","status":"active"},{"bound_failure":"mis-quantified","classification":"curated","display_name":"HTTP/2 Multiplexing Rate-Limit Bypass","dual_with":"response_amp","external_references":[],"family":"compute_amp","first_seen":"2026-07-15","id":"NRDAX-T0396","instances":[{"bundle_ref":"eth_geth_h2c_multiplex_connlimit_bypass","chain":"ethereum","discovery_origin":"original-research","external_references":[{"id":"geth-h2c-multiplexing-l4-connection-cap-bypass","kind":"nr-brief","title":"One prior-knowledge h2c connection multiplexes N eth_getLogs past an L4 per-connection cap on go-ethereum's JSON-RPC port","url":"https://nullrabbit.ai/research/geth-h2c-multiplexing-l4-connection-cap-bypass"}],"fidelity":"lab","primitive_id":"eth_geth_h2c_multiplex_connlimit_bypass"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The edge's rate limiter counts HTTP/2 cleartext (h2c) connections at layer 4 (per-IP connection count via limit_conn), while the backend (geth :8545) transparently terminates h2c and honors all multiplexed streams within it as independent requests. An attacker who prior-knowledge-upgrades a single TCP connection to h2c opens many concurrent streams (measured 20/20) inside that one connection, each carrying a full RPC call (e.g. eth_getLogs), so the edge sees '1 connection' while the backend processes N requests, yielding request/data-volume amplification (~43.9MB) with the per-IP connection cap never triggering. The defect class is a mismatch between the connection-granularity enforcement point and the stream-granularity request semantics of the multiplexed protocol; the fix-class is enforcing rate/connection limits at the stream (request) level for any multiplexed transport, or disabling/gating h2c cleartext upgrade at the edge so multiplexing cannot cross the limiter boundary.","name":"http2-multiplexing-ratelimit-bypass","producer_family":"rate_limiter_bypass","provenance_note":"imported from nr_registry cluster 'http2-multiplexing-ratelimit-bypass'","status":"active","surface":"rpc-api"},{"classification":"pending","display_name":"Missing State Metadata Panic Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0397","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Missing State Metadata Panic Crash","name":"missing-state-metadata-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'missing-state-metadata-panic-crash')","status":"active"},{"bound_failure":"no-bound","classification":"curated","display_name":"Unauthenticated Crypto Signing CPU Exhaustion","external_references":[],"family":"compute_amp","first_seen":"2026-07-15","id":"NRDAX-T0398","instances":[{"bundle_ref":"sui_bridge_sign_port_unauth_flood","chain":"sui","discovery_origin":"original-research","external_references":[],"fidelity":"lab","primitive_id":"sui_bridge_sign_port_unauth_flood"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The bridge signing server exposes its request-handling routes over plain HTTP with no authentication, no per-IP rate limit, and no concurrency/timeout cap — the only middleware layer checks body size, not request rate. An attacker sends cheap unauthenticated GETs to the signing endpoint, each of which the handler expands into backend RPC round-trips (fetch+verify) before signing, so request volume translates directly into backend work with no admission control to shed excess load. This lets a modest unauthenticated flood exhaust the signer's handling capacity, denying enough validators from completing signature assembly to halt the quorum (availability/censorship, not forgery).","name":"unauthenticated-crypto-signing-cpu-exhaustion","producer_family":"service_misconfig","provenance_note":"imported from nr_registry cluster 'unauthenticated-crypto-signing-cpu-exhaustion'","status":"active","surface":"control-plane"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Uninitialized Nil Map Access Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-16","id":"NRDAX-T0399","instances":[{"bundle_ref":"libp2p_autonatv2_nil_map_crash","chain":"libp2p","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"libp2p_autonatv2_nil_map_crash"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The AutoNAT v2 server never initialises its per-peer rate-limiter map before use; any well-formed inbound DialRequest on the /libp2p/autonat/2/dial-request stream reaches serveDialRequest -> rateLimiter.CompleteRequest, which performs a write ('assignment to entry in nil map') on that nil map. The fix-class is server-side state initialisation (allocate/guard the map before first write) rather than any input-validation or protocol change, so the defect is a missing-initialisation bug triggered by any valid protocol handshake, causing a remote unauthenticated panic/crash (availability DoS).","name":"uninitialized-nil-map-access-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'uninitialized-nil-map-access-panic'","status":"active","surface":"p2p-gossip"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Unsigned Integer Underflow Accounting Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-15","id":"NRDAX-T0400","instances":[{"bundle_ref":"conflux_snapshot_manifest_blame_underflow","chain":"conflux","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"conflux_snapshot_manifest_blame_underflow"},{"bundle_ref":"quinn_large_client_hello_panic","chain":"quic","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"quinn_large_client_hello_panic"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"The server's packet-coalescing space-accounting logic performs an unsigned subtraction of remaining datagram space when building its own coalesced Initial response, without checking that the incoming fragmented handshake (split across two CRYPTO frames in two coalesced Initial packets) hasn't already consumed more space than accounted for. An attacker sends a single UDP datagram with two coalesced QUIC Initial packets whose CRYPTO frames reconstruct an oversized (~1222B) ClientHello, triggering an 'attempt to subtract with overflow' at the coalescing arithmetic and crashing the server process pre-handshake. The fix-class is bounds-checked/saturating space accounting in the response-coalescing path, making this the same technique as any other unsigned-underflow-panic in QUIC packet-space bookkeeping triggered by oversized/fragmented handshake input.","name":"unsigned-integer-underflow-accounting-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'unsigned-integer-underflow-accounting-panic'","status":"active","surface":"p2p-gossip"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Boundary-Check Off-By-One Index OOB Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-17","id":"NRDAX-T0401","instances":[{"bundle_ref":"cosmos_tx_malformed_authinfo_nil_panic","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"cosmos_tx_malformed_authinfo_nil_panic"},{"bundle_ref":"nimiq_proposal_signer_oob","chain":"nimiq","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"nimiq_proposal_signer_oob"}],"lineage":{"deployments":2,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"The node's proposal-ingest path bounds-checks an attacker-supplied `signer` slot index against the validator-set size using a strict `>` comparison instead of `>=`, so the boundary value `signer == num_validators` passes the check. That value is then used to index the validator array via `get_validator_by_slot_band`, causing an out-of-bounds access, and this happens before any signature verification, so an unauthenticated peer can gossip a single crafted, unsigned proposal to crash every receiving validator. Fix-class: correct the off-by-one bound check (or otherwise validate/clamp the index) prior to array indexing, closing the pre-auth OOB panic (CWE-125/193).","name":"boundary-check-off-by-one-index-oob-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'boundary-check-off-by-one-index-oob-panic'","status":"active","surface":"consensus-ingest"},{"classification":"pending","display_name":"Burn Inflation Reward Mismatch Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0402","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Burn Inflation Reward Mismatch Panic","name":"burn-inflation-reward-mismatch-panic","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'burn-inflation-reward-mismatch-panic')","status":"active"},{"classification":"pending","display_name":"DHT First-Record Verification Bypass","external_references":[],"family":null,"first_seen":"2026-07-17","id":"NRDAX-T0403","instances":[{"bundle_ref":"nimiq_dht_get_first_record_poison","chain":"nimiq","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"nimiq_dht_get_first_record_poison"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"handle_dht_get only creates the DhtResults accumulator when the FIRST returned Kademlia record verifies successfully; it never falls back to a later valid record if that first responder's record fails verification. A malicious peer wins the race by answering the get first with a well-formed but unverifiable record (e.g. correct-length but all-zero signature), causing the accumulator to never be initialized. Every subsequent honest, valid record is then compared against the missing/poisoned state and discarded as inconsistent, denying the querying node the real value and blocking peer/validator discovery and routing (improper handling of an unusual/exceptional first-response condition, CWE-754).","name":"dht-first-record-verification-bypass","out_of_scope":true,"producer_family":"gossip_abuse","provenance_note":"imported from nr_registry cluster 'dht-first-record-verification-bypass'","status":"active"},{"classification":"pending","display_name":"MEV Bid Double-Release Crash","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0404","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"MEV Bid Double-Release Crash","name":"mev-bid-double-release-crash","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'mev-bid-double-release-crash')","status":"active"},{"classification":"pending","display_name":"Oversized WASM Memory Grow Panic","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0405","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Oversized WASM Memory Grow Panic","name":"oversized-wasm-memory-grow-panic","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'oversized-wasm-memory-grow-panic')","status":"active"},{"classification":"pending","display_name":"QUIC Certificate Validation Panic","external_references":[{"id":"GHPR-libp2p-rust-libp2p-6525","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0406","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC Certificate Validation Panic","name":"quic-certificate-validation-panic","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-certificate-validation-panic')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Signature Count Integer Overflow Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-17","id":"NRDAX-T0407","instances":[{"bundle_ref":"namada_multisig_256key_sig_overflow","chain":"namada","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"namada_multisig_256key_sig_overflow"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"Tx::verify_signatures counts/indexes the public keys in a Section::Authorization using a u8-width counter; a single unauthenticated transaction whose Authorization section carries 256+ Ed25519 public keys (with matching valid signatures) overflows that u8 during mempool CheckTx. The overflow triggers a panic, crashing the validating node from one crafted broadcast_tx_sync submission. Fix-class is bounding/validating the authorization key-count (or widening the counter) before/during signature verification, i.e. an integer-overflow-in-untrusted-length-field defect (CWE-190) in mempool tx validation.","name":"signature-count-integer-overflow-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'signature-count-integer-overflow-panic'","status":"active","surface":"consensus-ingest"},{"bound_failure":"late","classification":"curated","display_name":"Unbounded Address List Validation CPU Exhaustion","dual_with":"memory_amp","external_references":[],"family":"compute_amp","first_seen":"2026-07-17","id":"NRDAX-T0408","instances":[{"bundle_ref":"cosmwasm_validate_basic_address_count","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"cosmwasm_validate_basic_address_count"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"wasmd message types (MsgStoreCode, MsgStoreAndInstantiateContract, MsgUpdateInstantiateConfig, MsgAddCodeUploadParamsAddresses, etc.) carry an unbounded AccessConfig.Addresses/msg.Addresses list that ValidateBasic() de-duplicates via a map, and this validation runs during ABCI CheckTx before antehandler signature verification. An attacker submits a single unsigned tx via broadcast_tx_sync packing tens of thousands of distinct addresses (bounded only by tx-size gas cost and CometBFT max_bytes), causing large memory allocation and map-operation slowdown in the mempool of every node that receives it. The fix class is bounding/validating list length (or moving the check post-auth) in ValidateBasic before the map de-dup step.","name":"unbounded-address-list-validation-cpu-exhaustion","producer_family":"memory_amp","provenance_note":"imported from nr_registry cluster 'unbounded-address-list-validation-cpu-exhaustion'","status":"active","surface":"consensus-ingest"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3007","name":"Exploit Consensus Logic","url":"https://aadapt.mitre.org/techniques/ADT3007"},"display_name":"Blocked Address Validation Bypass","external_references":[],"family":null,"first_seen":"2026-07-19","id":"NRDAX-T0409","instances":[{"bundle_ref":"cosmos_vesting_blocked_address","chain":"cosmos","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"GHSA-4j93-fm92-rp4m","kind":"ghsa","url":"https://github.com/advisories/GHSA-4j93-fm92-rp4m"}],"fidelity":"lab","primitive_id":"cosmos_vesting_blocked_address"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"ASA-2024-003 / GHSA-4j93-fm92-rp4m (cosmos-sdk cosmos-sdk <= v0.50.3 / <= v0.47.8): x/auth/vesting MsgCreateVestingAccount / MsgCreatePermanentLockedAccount did not reject a blocked `to_address` (a module account on the bank blocklist), so one permissionless signed tx could create a vesting account at an uninitialised blocked module address; a later GetModuleAccount on it panics -> chain halt (CWE-20). Confirmed live: the signed tx reaches DeliverTx on patched gaiad v21 and is rejected with '<addr> is not allowed to receive funds: unauthorized' (the fix's guard); on a vulnerable node it halts the chain. Fixed v0.50.4 / v0.47.9. https://github.com/advisories/GHSA-4j93-fm92-rp4m","name":"blocked-address-validation-bypass","out_of_scope":true,"producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'blocked-address-validation-bypass'","status":"active"},{"classification":"pending","display_name":"Gossip Message-ID Spoof Suppression","external_references":[{"id":"GHPR-ethereum-optimism-optimism-21804","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0410","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gossip Message-ID Spoof Suppression","name":"gossip-messageid-spoof-suppression","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'gossip-messageid-spoof-suppression')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3007","name":"Exploit Consensus Logic","url":"https://aadapt.mitre.org/techniques/ADT3007"},"display_name":"SIGHASH_SINGLE Missing-Output Validation Gap","external_references":[],"family":null,"first_seen":"2026-07-20","id":"NRDAX-T0411","instances":[{"bundle_ref":"zebra_sighash_single_missing_output","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"zebra_sighash_single_missing_output"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The node's transaction sighash routine fails to reject SIGHASH_SINGLE inputs whose index is >= the number of outputs; instead of throwing (the spec-mandated behavior), it silently substitutes an empty output set when computing the signature digest. An attacker crafts a transparent transaction with more inputs than outputs and signs the offending input with SIGHASH_SINGLE at an out-of-range index against this empty-set digest, producing a signature the defective node validates and accepts into its mempool/block template while spec-compliant nodes reject it. This divergence yields a direct block-validity consensus split between vulnerable and correct implementations.","name":"sighash-single-index-validation-gap","out_of_scope":true,"producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'sighash-single-index-validation-gap'","status":"active"},{"classification":"pending","display_name":"Silent State-Read Error Consensus Split","external_references":[],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0412","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Silent State-Read Error Consensus Split","name":"silent-state-read-error-consensus-split","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'silent-state-read-error-consensus-split')","status":"active"},{"classification":"pending","display_name":"Duplicate Block Verification Deadlock","external_references":[{"id":"GHPR-ava-labs-avalanchego-5690","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0413","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Duplicate Block Verification Deadlock","name":"duplicate-block-verification-deadlock","producer_family":"consensus","provenance_note":"known-but-not-reproduced coverage gap (technique 'duplicate-block-verification-deadlock')","status":"active"},{"classification":"pending","crosswalk":{"framework":"aadapt","id":"ADT3007","name":"Exploit Consensus Logic","url":"https://aadapt.mitre.org/techniques/ADT3007"},"display_name":"Invalid Sighash Type Validation Gap","external_references":[],"family":null,"first_seen":"2026-07-21","id":"NRDAX-T0414","instances":[{"bundle_ref":"zebra_invalid_sighash_hashtype","chain":"zcash","discovery_origin":"reverse-engineered-cve","external_references":[],"fidelity":"lab","primitive_id":"zebra_invalid_sighash_hashtype"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":1,"upper_bound":1},"mechanism":"The node's transaction-verification layer fails to enforce the rule that a transparent-input signature's trailing hash-type byte must be one of the known canonical values (ALL/NONE/SINGLE and their ANYONECANPAY variants); this validation, previously enforced in an older verifier, was dropped during a parsing/verification refactor. An attacker submits a validly-signed transaction whose hash-type byte is an unrecognized value, which the defective node silently masks to a canonical type when computing the sighash digest instead of rejecting it outright. This causes the vulnerable node to accept and relay/mine a transaction that reference implementations reject, producing a deterministic block/mempool-validity consensus split between patched and unpatched nodes.","name":"invalid-sighash-type-validation-gap","out_of_scope":true,"producer_family":"consensus_abuse","provenance_note":"imported from nr_registry cluster 'invalid-sighash-type-validation-gap'","status":"active"},{"classification":"pending","display_name":"Post-Sync Block-Response Panic Crash","external_references":[{"id":"GHPR-cometbft-cometbft-5959","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0415","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Post-Sync Block-Response Panic Crash","name":"post-sync-block-response-panic-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'post-sync-block-response-panic-crash')","status":"active"},{"classification":"pending","display_name":"QUIC QLogger Nil-Pointer Crash","external_references":[{"id":"GHPR-quic-go-quic-go-5759","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0416","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"QUIC QLogger Nil-Pointer Crash","name":"quic-qlogger-nil-pointer-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'quic-qlogger-nil-pointer-crash')","status":"active"},{"bound_failure":"absent-invariant","classification":"curated","display_name":"Malformed RLP Field-Length Panic","external_references":[],"family":"fault_termination","first_seen":"2026-07-21","id":"NRDAX-T0417","instances":[{"bundle_ref":"conflux_light_storageroots_mptvalue_panic","chain":"conflux","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/Conflux-Chain/conflux-rust/pull/3497","kind":"vendor-advisory","url":"https://github.com/Conflux-Chain/conflux-rust/pull/3497"}],"fidelity":"lab","primitive_id":"conflux_light_storageroots_mptvalue_panic"},{"bundle_ref":"conflux_manifest_trienode_hash_panic","chain":"conflux","discovery_origin":"reverse-engineered-cve","external_references":[{"id":"https://github.com/Conflux-Chain/conflux-rust/pull/3535","kind":"vendor-advisory","url":"https://github.com/Conflux-Chain/conflux-rust/pull/3535"}],"fidelity":"lab","primitive_id":"conflux_manifest_trienode_hash_panic"}],"lineage":{"deployments":1,"groups":[],"independent_stacks":0,"is_lower_bound":true,"unknown_instances":2,"upper_bound":2},"mechanism":"conflux-rust#3497 (conflux-rust light protocol): a single unauthenticated StorageRoots (clp msg_id 0x1b) whose roots[0].root.delta = RLP list [3] makes MptValue<H256>::decode hit `n => panic!` during RLP decode, before request-matching. Victim = a LIGHT node (its clp client handler decodes StorageRoots). Verified live vs vulnerable v3.0.3 (f44f1cb, node_type=light): after the clp handshake (StatusPingV2/StatusPongV2), one 0x1b panics thread 'Socket IO Worker' at primitives/src/storage.rs:144; ~2 msgs freeze P2P. Fixed by returning a DecoderError. https://github.com/Conflux-Chain/conflux-rust/pull/3497","name":"malformed-rlp-field-length-panic","producer_family":"compute_amp","provenance_note":"imported from nr_registry cluster 'malformed-rlp-field-length-panic'","status":"active","surface":"p2p-gossip"},{"classification":"pending","display_name":"ENR Sequence Inflation Refresh DoS","external_references":[{"id":"GHPR-NethermindEth-nethermind-12556","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0418","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"ENR Sequence Inflation Refresh DoS","name":"enr-sequence-inflation-refresh-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'enr-sequence-inflation-refresh-dos')","status":"active"},{"classification":"pending","display_name":"Snapshot Manifest Boundary Validation Crash","external_references":[{"id":"GHPR-Conflux-Chain-conflux-rust-3563","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0419","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Snapshot Manifest Boundary Validation Crash","name":"snapshot-manifest-boundary-validation-crash","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'snapshot-manifest-boundary-validation-crash')","status":"active"},{"classification":"pending","display_name":"Stale Pending Block Cache DoS","external_references":[{"id":"GHPR-erigontech-erigon-22326","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0420","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Stale Pending Block Cache DoS","name":"stale-pending-block-cache-dos","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'stale-pending-block-cache-dos')","status":"active"},{"classification":"pending","display_name":"Yamux Oversized Frame Hang","external_references":[{"id":"GHSA-hmj8-5xmh-5573","kind":"ghsa","url":"https://github.com/advisories/GHSA-hmj8-5xmh-5573"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0421","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Yamux Oversized Frame Hang","name":"yamux-oversized-frame-hang","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'yamux-oversized-frame-hang')","status":"active"},{"classification":"pending","display_name":"Mempool Transaction Heap Amplification","external_references":[{"id":"GHREL-cometbft-cometbft-v0.38.25","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0422","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Mempool Transaction Heap Amplification","name":"mempool-transaction-heap-amplification","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'mempool-transaction-heap-amplification')","status":"active"},{"classification":"pending","display_name":"Gossip Bid Increment Spam CPU Burn","external_references":[{"id":"GHPR-ChainSafe-lodestar-9706","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0423","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Gossip Bid Increment Spam CPU Burn","name":"gossip-bid-increment-spam-cpu-burn","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'gossip-bid-increment-spam-cpu-burn')","status":"active"},{"classification":"pending","display_name":"Hex Input Parsing Panic","external_references":[{"id":"GHPR-filecoin-project-venus-6562","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0424","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Hex Input Parsing Panic","name":"hex-input-parsing-panic","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'hex-input-parsing-panic')","status":"active"},{"classification":"pending","display_name":"Invalid UTF-8 Parsing Infinite Loop","external_references":[{"id":"CVE-2026-56852","kind":"cve","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56852"}],"family":null,"first_seen":"2026-01-01","id":"NRDAX-T0425","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Invalid UTF-8 Parsing Infinite Loop","name":"invalid-utf8-parsing-infinite-loop","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'invalid-utf8-parsing-infinite-loop')","status":"active"},{"classification":"pending","display_name":"Sandbox Launcher Race Condition Hang","external_references":[{"id":"GHPR-dfinity-ic-10932","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0426","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"Sandbox Launcher Race Condition Hang","name":"sandbox-launcher-race-condition-hang","producer_family":"network-rpc","provenance_note":"known-but-not-reproduced coverage gap (technique 'sandbox-launcher-race-condition-hang')","status":"active"},{"classification":"pending","display_name":"SSZ Fork Mismatch Nil-Deref","external_references":[{"id":"GHPR-erigontech-erigon-22797","kind":"vendor-advisory"}],"family":null,"first_seen":"2020-01-01","id":"NRDAX-T0427","instances":[],"lineage":{"deployments":0,"groups":[],"independent_stacks":0,"is_lower_bound":false,"unknown_instances":0,"upper_bound":0},"mechanism":"SSZ Fork Mismatch Nil-Deref","name":"ssz-fork-mismatch-nil-deref","producer_family":"network-p2p","provenance_note":"known-but-not-reproduced coverage gap (technique 'ssz-fork-mismatch-nil-deref')","status":"active"}],"total":427}