{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-28402",
        "tracking": {
            "current_release_date": "2026-03-23T01:22:18.080424Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-28402",
            "initial_release_date": "2026-02-27T21:38:42.033433Z",
            "revision_history": [
                {
                    "date": "2026-02-27T21:38:42.033433Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T21:38:52.236227Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-02-27T22:25:33.072009Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-02-27T22:25:42.615989Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T07:34:54.926231Z",
                    "number": "5",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T14:01:32.368690Z",
                    "number": "6",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (78).| Products created (4).| References created (6).| CWES updated (1)."
                },
                {
                    "date": "2026-02-28T14:01:46.832194Z",
                    "number": "7",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-02-28T14:13:41.384659Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-02-28T14:13:44.749925Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-03T21:38:50.445185Z",
                    "number": "10",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-03-03T21:38:55.120343Z",
                    "number": "11",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-03-20T09:37:36.993365Z",
                    "number": "12",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-03-20T09:37:40.384188Z",
                    "number": "13",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "13"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<1.2.2",
                                "product": {
                                    "name": "vers:unknown/<1.2.2",
                                    "product_id": "CSAFPID-5736458"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0",
                                "product": {
                                    "name": "vers:unknown/v0.1.0",
                                    "product_id": "CSAFPID-3770837"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0-rc.0",
                                "product": {
                                    "name": "vers:unknown/v0.1.0-rc.0",
                                    "product_id": "CSAFPID-3770838"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0-rc.1",
                                "product": {
                                    "name": "vers:unknown/v0.1.0-rc.1",
                                    "product_id": "CSAFPID-3770839"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0-rc.2",
                                "product": {
                                    "name": "vers:unknown/v0.1.0-rc.2",
                                    "product_id": "CSAFPID-3770840"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.1.0-rc.3",
                                "product": {
                                    "name": "vers:unknown/v0.1.0-rc.3",
                                    "product_id": "CSAFPID-3770841"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.10.0",
                                "product": {
                                    "name": "vers:unknown/v0.10.0",
                                    "product_id": "CSAFPID-3770842"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.11.0",
                                "product": {
                                    "name": "vers:unknown/v0.11.0",
                                    "product_id": "CSAFPID-3770843"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.11.1",
                                "product": {
                                    "name": "vers:unknown/v0.11.1",
                                    "product_id": "CSAFPID-3770844"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.11.2",
                                "product": {
                                    "name": "vers:unknown/v0.11.2",
                                    "product_id": "CSAFPID-3770845"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.11.3",
                                "product": {
                                    "name": "vers:unknown/v0.11.3",
                                    "product_id": "CSAFPID-3770846"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.11.4",
                                "product": {
                                    "name": "vers:unknown/v0.11.4",
                                    "product_id": "CSAFPID-3770847"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.11.5",
                                "product": {
                                    "name": "vers:unknown/v0.11.5",
                                    "product_id": "CSAFPID-3770848"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.12.0",
                                "product": {
                                    "name": "vers:unknown/v0.12.0",
                                    "product_id": "CSAFPID-3770849"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.12.1",
                                "product": {
                                    "name": "vers:unknown/v0.12.1",
                                    "product_id": "CSAFPID-3770850"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.13.0",
                                "product": {
                                    "name": "vers:unknown/v0.13.0",
                                    "product_id": "CSAFPID-3770851"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.13.1",
                                "product": {
                                    "name": "vers:unknown/v0.13.1",
                                    "product_id": "CSAFPID-3770852"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.14.0",
                                "product": {
                                    "name": "vers:unknown/v0.14.0",
                                    "product_id": "CSAFPID-3770853"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.15.0",
                                "product": {
                                    "name": "vers:unknown/v0.15.0",
                                    "product_id": "CSAFPID-3770854"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.16.0",
                                "product": {
                                    "name": "vers:unknown/v0.16.0",
                                    "product_id": "CSAFPID-3770855"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.16.1",
                                "product": {
                                    "name": "vers:unknown/v0.16.1",
                                    "product_id": "CSAFPID-3770856"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.17.0",
                                "product": {
                                    "name": "vers:unknown/v0.17.0",
                                    "product_id": "CSAFPID-3770857"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.18.0",
                                "product": {
                                    "name": "vers:unknown/v0.18.0",
                                    "product_id": "CSAFPID-3770858"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.19.0",
                                "product": {
                                    "name": "vers:unknown/v0.19.0",
                                    "product_id": "CSAFPID-3770859"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.2.0",
                                "product": {
                                    "name": "vers:unknown/v0.2.0",
                                    "product_id": "CSAFPID-3770860"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.2.1",
                                "product": {
                                    "name": "vers:unknown/v0.2.1",
                                    "product_id": "CSAFPID-3770861"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.2.2",
                                "product": {
                                    "name": "vers:unknown/v0.2.2",
                                    "product_id": "CSAFPID-3770862"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.20.0",
                                "product": {
                                    "name": "vers:unknown/v0.20.0",
                                    "product_id": "CSAFPID-3770863"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.20.1",
                                "product": {
                                    "name": "vers:unknown/v0.20.1",
                                    "product_id": "CSAFPID-3770864"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.20.2",
                                "product": {
                                    "name": "vers:unknown/v0.20.2",
                                    "product_id": "CSAFPID-3770865"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.20.3",
                                "product": {
                                    "name": "vers:unknown/v0.20.3",
                                    "product_id": "CSAFPID-3770866"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.20.4",
                                "product": {
                                    "name": "vers:unknown/v0.20.4",
                                    "product_id": "CSAFPID-3770867"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.20.5",
                                "product": {
                                    "name": "vers:unknown/v0.20.5",
                                    "product_id": "CSAFPID-3770868"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.21.0",
                                "product": {
                                    "name": "vers:unknown/v0.21.0",
                                    "product_id": "CSAFPID-3770869"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.21.1",
                                "product": {
                                    "name": "vers:unknown/v0.21.1",
                                    "product_id": "CSAFPID-3770870"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.22.0",
                                "product": {
                                    "name": "vers:unknown/v0.22.0",
                                    "product_id": "CSAFPID-3770871"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.22.1",
                                "product": {
                                    "name": "vers:unknown/v0.22.1",
                                    "product_id": "CSAFPID-3770872"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.22.2",
                                "product": {
                                    "name": "vers:unknown/v0.22.2",
                                    "product_id": "CSAFPID-3770873"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.22.3",
                                "product": {
                                    "name": "vers:unknown/v0.22.3",
                                    "product_id": "CSAFPID-3770874"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.23.0",
                                "product": {
                                    "name": "vers:unknown/v0.23.0",
                                    "product_id": "CSAFPID-3770875"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.0",
                                "product": {
                                    "name": "vers:unknown/v0.24.0",
                                    "product_id": "CSAFPID-3770876"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.1",
                                "product": {
                                    "name": "vers:unknown/v0.24.1",
                                    "product_id": "CSAFPID-3770877"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.2",
                                "product": {
                                    "name": "vers:unknown/v0.24.2",
                                    "product_id": "CSAFPID-3770878"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.3",
                                "product": {
                                    "name": "vers:unknown/v0.24.3",
                                    "product_id": "CSAFPID-3770879"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.24.4",
                                "product": {
                                    "name": "vers:unknown/v0.24.4",
                                    "product_id": "CSAFPID-3770880"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.3.0",
                                "product": {
                                    "name": "vers:unknown/v0.3.0",
                                    "product_id": "CSAFPID-3770881"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.3.1",
                                "product": {
                                    "name": "vers:unknown/v0.3.1",
                                    "product_id": "CSAFPID-3770882"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.3.2",
                                "product": {
                                    "name": "vers:unknown/v0.3.2",
                                    "product_id": "CSAFPID-3770883"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.3.3",
                                "product": {
                                    "name": "vers:unknown/v0.3.3",
                                    "product_id": "CSAFPID-3770884"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.4.0",
                                "product": {
                                    "name": "vers:unknown/v0.4.0",
                                    "product_id": "CSAFPID-3770885"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.4.1",
                                "product": {
                                    "name": "vers:unknown/v0.4.1",
                                    "product_id": "CSAFPID-3770886"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.5.0",
                                "product": {
                                    "name": "vers:unknown/v0.5.0",
                                    "product_id": "CSAFPID-3770887"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.5.1",
                                "product": {
                                    "name": "vers:unknown/v0.5.1",
                                    "product_id": "CSAFPID-3770888"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.5.2",
                                "product": {
                                    "name": "vers:unknown/v0.5.2",
                                    "product_id": "CSAFPID-3770889"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.5.3",
                                "product": {
                                    "name": "vers:unknown/v0.5.3",
                                    "product_id": "CSAFPID-3770890"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.5.4",
                                "product": {
                                    "name": "vers:unknown/v0.5.4",
                                    "product_id": "CSAFPID-3770891"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.6.0",
                                "product": {
                                    "name": "vers:unknown/v0.6.0",
                                    "product_id": "CSAFPID-3770892"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.7.0",
                                "product": {
                                    "name": "vers:unknown/v0.7.0",
                                    "product_id": "CSAFPID-3770893"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.0",
                                "product": {
                                    "name": "vers:unknown/v0.8.0",
                                    "product_id": "CSAFPID-3770894"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.1",
                                "product": {
                                    "name": "vers:unknown/v0.8.1",
                                    "product_id": "CSAFPID-3770895"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.2",
                                "product": {
                                    "name": "vers:unknown/v0.8.2",
                                    "product_id": "CSAFPID-3770896"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.8.3",
                                "product": {
                                    "name": "vers:unknown/v0.8.3",
                                    "product_id": "CSAFPID-3770897"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v0.9.0",
                                "product": {
                                    "name": "vers:unknown/v0.9.0",
                                    "product_id": "CSAFPID-3770898"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0",
                                "product": {
                                    "name": "vers:unknown/v1.0.0",
                                    "product_id": "CSAFPID-3770899"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-rc.0",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-rc.0",
                                    "product_id": "CSAFPID-3770900"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-rc.1",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-rc.1",
                                    "product_id": "CSAFPID-3770901"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-rc.2",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-rc.2",
                                    "product_id": "CSAFPID-3770902"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-rc.3",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-rc.3",
                                    "product_id": "CSAFPID-3770903"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-rc.4",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-rc.4",
                                    "product_id": "CSAFPID-3770904"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.0-rc.5",
                                "product": {
                                    "name": "vers:unknown/v1.0.0-rc.5",
                                    "product_id": "CSAFPID-3770905"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.1",
                                "product": {
                                    "name": "vers:unknown/v1.0.1",
                                    "product_id": "CSAFPID-3770906"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.2",
                                "product": {
                                    "name": "vers:unknown/v1.0.2",
                                    "product_id": "CSAFPID-3770907"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.3",
                                "product": {
                                    "name": "vers:unknown/v1.0.3",
                                    "product_id": "CSAFPID-3770908"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.4",
                                "product": {
                                    "name": "vers:unknown/v1.0.4",
                                    "product_id": "CSAFPID-3770909"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.5",
                                "product": {
                                    "name": "vers:unknown/v1.0.5",
                                    "product_id": "CSAFPID-3770910"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.6",
                                "product": {
                                    "name": "vers:unknown/v1.0.6",
                                    "product_id": "CSAFPID-3770911"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.7",
                                "product": {
                                    "name": "vers:unknown/v1.0.7",
                                    "product_id": "CSAFPID-3770912"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.8",
                                "product": {
                                    "name": "vers:unknown/v1.0.8",
                                    "product_id": "CSAFPID-3770913"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.0.9",
                                "product": {
                                    "name": "vers:unknown/v1.0.9",
                                    "product_id": "CSAFPID-3770914"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.0",
                                "product": {
                                    "name": "vers:unknown/v1.1.0",
                                    "product_id": "CSAFPID-5749579"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.1.1",
                                "product": {
                                    "name": "vers:unknown/v1.1.1",
                                    "product_id": "CSAFPID-5749580"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.0",
                                "product": {
                                    "name": "vers:unknown/v1.2.0",
                                    "product_id": "CSAFPID-5749581"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/v1.2.1",
                                "product": {
                                    "name": "vers:unknown/v1.2.1",
                                    "product_id": "CSAFPID-5749582"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "core-rs-albatross"
                    }
                ],
                "category": "vendor",
                "name": "nimiq"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-28402",
            "cwe": {
                "id": "CWE-354",
                "name": "Improper Validation of Integrity Check Value"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised validator that is elected as proposer can publish a macro block proposal where `header.body_root` does not match the actual macro body hash. The proposal can pass proposal verification because the macro proposal verification path validates the header but does not validate the binding `body_root == hash(body)`; later code expects this binding and may panic on mismatch, crashing validators. Note that the impact is only for validator nodes. The patch for this vulnerability is formally released as part of v1.2.2. The patch adds the corresponding body root verification in the proposal checks. No known workarounds are available.",
                    "title": "cveprojectv5 - https://www.cve.org/CVERecord?id=CVE-2026-28402"
                },
                {
                    "category": "description",
                    "text": "nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised validator that is elected as proposer can publish a macro block proposal where `header.body_root` does not match the actual macro body hash. The proposal can pass proposal verification because the macro proposal verification path validates the header but does not validate the binding `body_root == hash(body)`; later code expects this binding and may panic on mismatch, crashing validators. Note that the impact is only for validator nodes. The patch for this vulnerability is formally released as part of v1.2.2. The patch adds the corresponding body root verification in the proposal checks. No known workarounds are available.",
                    "title": "nvd - https://nvd.nist.gov/vuln/detail/CVE-2026-28402"
                },
                {
                    "category": "description",
                    "text": "nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.2.2, a malicious or compromised validator that is elected as proposer can publish a macro block proposal where `header.body_root` does not match the actual macro body hash. The proposal can pass proposal verification because the macro proposal verification path validates the header but does not validate the binding `body_root == hash(body)`; later code expects this binding and may panic on mismatch, crashing validators. Note that the impact is only for validator nodes. The patch for this vulnerability is formally released as part of v1.2.2. The patch adds the corresponding body root verification in the proposal checks. No known workarounds are available.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28402.json?alt=media"
                },
                {
                    "category": "other",
                    "text": "0.00021",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "3.9",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "The value of the most recent EPSS score, There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-5736458",
                    "CSAFPID-3770837",
                    "CSAFPID-3770838",
                    "CSAFPID-3770839",
                    "CSAFPID-3770840",
                    "CSAFPID-3770841",
                    "CSAFPID-3770842",
                    "CSAFPID-3770843",
                    "CSAFPID-3770844",
                    "CSAFPID-3770845",
                    "CSAFPID-3770846",
                    "CSAFPID-3770847",
                    "CSAFPID-3770848",
                    "CSAFPID-3770849",
                    "CSAFPID-3770850",
                    "CSAFPID-3770851",
                    "CSAFPID-3770852",
                    "CSAFPID-3770853",
                    "CSAFPID-3770854",
                    "CSAFPID-3770855",
                    "CSAFPID-3770856",
                    "CSAFPID-3770857",
                    "CSAFPID-3770858",
                    "CSAFPID-3770859",
                    "CSAFPID-3770860",
                    "CSAFPID-3770861",
                    "CSAFPID-3770862",
                    "CSAFPID-3770863",
                    "CSAFPID-3770864",
                    "CSAFPID-3770865",
                    "CSAFPID-3770866",
                    "CSAFPID-3770867",
                    "CSAFPID-3770868",
                    "CSAFPID-3770869",
                    "CSAFPID-3770870",
                    "CSAFPID-3770871",
                    "CSAFPID-3770872",
                    "CSAFPID-3770873",
                    "CSAFPID-3770874",
                    "CSAFPID-3770875",
                    "CSAFPID-3770876",
                    "CSAFPID-3770877",
                    "CSAFPID-3770878",
                    "CSAFPID-3770879",
                    "CSAFPID-3770880",
                    "CSAFPID-3770881",
                    "CSAFPID-3770882",
                    "CSAFPID-3770883",
                    "CSAFPID-3770884",
                    "CSAFPID-3770885",
                    "CSAFPID-3770886",
                    "CSAFPID-3770887",
                    "CSAFPID-3770888",
                    "CSAFPID-3770889",
                    "CSAFPID-3770890",
                    "CSAFPID-3770891",
                    "CSAFPID-3770892",
                    "CSAFPID-3770893",
                    "CSAFPID-3770894",
                    "CSAFPID-3770895",
                    "CSAFPID-3770896",
                    "CSAFPID-3770897",
                    "CSAFPID-3770898",
                    "CSAFPID-3770899",
                    "CSAFPID-3770900",
                    "CSAFPID-3770901",
                    "CSAFPID-3770902",
                    "CSAFPID-3770903",
                    "CSAFPID-3770904",
                    "CSAFPID-3770905",
                    "CSAFPID-3770906",
                    "CSAFPID-3770907",
                    "CSAFPID-3770908",
                    "CSAFPID-3770909",
                    "CSAFPID-3770910",
                    "CSAFPID-3770911",
                    "CSAFPID-3770912",
                    "CSAFPID-3770913",
                    "CSAFPID-3770914",
                    "CSAFPID-5749579",
                    "CSAFPID-5749580",
                    "CSAFPID-5749581",
                    "CSAFPID-5749582"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-28402"
                },
                {
                    "category": "external",
                    "summary": "Source raw - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28402.json"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28402"
                },
                {
                    "category": "external",
                    "summary": "Source raw - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-28402"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-28402.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?cve=CVE-2026-28402"
                },
                {
                    "category": "external",
                    "summary": "Source raw - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/nimiq/core-rs-albatross/security/advisories/GHSA-7wh6-rmxx-ww47"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/nimiq/core-rs-albatross/pull/3623"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/nimiq/core-rs-albatross/commit/6454c26d966858c5520f55739a30b94c17656c85"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "https://github.com/nimiq/core-rs-albatross/releases/tag/v1.2.2"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28402.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28402"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "products": [
                        "CSAFPID-3770837",
                        "CSAFPID-3770838",
                        "CSAFPID-3770839",
                        "CSAFPID-3770840",
                        "CSAFPID-3770841",
                        "CSAFPID-3770842",
                        "CSAFPID-3770843",
                        "CSAFPID-3770844",
                        "CSAFPID-3770845",
                        "CSAFPID-3770846",
                        "CSAFPID-3770847",
                        "CSAFPID-3770848",
                        "CSAFPID-3770849",
                        "CSAFPID-3770850",
                        "CSAFPID-3770851",
                        "CSAFPID-3770852",
                        "CSAFPID-3770853",
                        "CSAFPID-3770854",
                        "CSAFPID-3770855",
                        "CSAFPID-3770856",
                        "CSAFPID-3770857",
                        "CSAFPID-3770858",
                        "CSAFPID-3770859",
                        "CSAFPID-3770860",
                        "CSAFPID-3770861",
                        "CSAFPID-3770862",
                        "CSAFPID-3770863",
                        "CSAFPID-3770864",
                        "CSAFPID-3770865",
                        "CSAFPID-3770866",
                        "CSAFPID-3770867",
                        "CSAFPID-3770868",
                        "CSAFPID-3770869",
                        "CSAFPID-3770870",
                        "CSAFPID-3770871",
                        "CSAFPID-3770872",
                        "CSAFPID-3770873",
                        "CSAFPID-3770874",
                        "CSAFPID-3770875",
                        "CSAFPID-3770876",
                        "CSAFPID-3770877",
                        "CSAFPID-3770878",
                        "CSAFPID-3770879",
                        "CSAFPID-3770880",
                        "CSAFPID-3770881",
                        "CSAFPID-3770882",
                        "CSAFPID-3770883",
                        "CSAFPID-3770884",
                        "CSAFPID-3770885",
                        "CSAFPID-3770886",
                        "CSAFPID-3770887",
                        "CSAFPID-3770888",
                        "CSAFPID-3770889",
                        "CSAFPID-3770890",
                        "CSAFPID-3770891",
                        "CSAFPID-3770892",
                        "CSAFPID-3770893",
                        "CSAFPID-3770894",
                        "CSAFPID-3770895",
                        "CSAFPID-3770896",
                        "CSAFPID-3770897",
                        "CSAFPID-3770898",
                        "CSAFPID-3770899",
                        "CSAFPID-3770900",
                        "CSAFPID-3770901",
                        "CSAFPID-3770902",
                        "CSAFPID-3770903",
                        "CSAFPID-3770904",
                        "CSAFPID-3770905",
                        "CSAFPID-3770906",
                        "CSAFPID-3770907",
                        "CSAFPID-3770908",
                        "CSAFPID-3770909",
                        "CSAFPID-3770910",
                        "CSAFPID-3770911",
                        "CSAFPID-3770912",
                        "CSAFPID-3770913",
                        "CSAFPID-3770914",
                        "CSAFPID-5736458",
                        "CSAFPID-5749579",
                        "CSAFPID-5749580",
                        "CSAFPID-5749581",
                        "CSAFPID-5749582"
                    ]
                }
            ],
            "title": "CVE-2026-28402"
        }
    ]
}