- Reported
-
- Issued
-
- Package
-
nostr
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#nostr
#nip-44
#panic
- References
-
- CVSS Score
- 7.5
HIGH
- CVSS Details
-
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality Impact
- None
- Integrity Impact
- None
- Availability Impact
- High
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Patched
-
>=0.44.5, <0.45.0-alpha.1
>=0.45.0-alpha.5
- Affected Functions
- Version
nostr::nips::nip44::decrypt
-
>=0.26.0, <0.44.5
>=0.45.0-alpha.1, <0.45.0-alpha.5
nostr::nips::nip44::decrypt_to_bytes
-
>=0.26.0, <0.44.5
>=0.45.0-alpha.1, <0.45.0-alpha.5
nostr::nips::nip44::v2::decrypt_to_bytes
-
>=0.26.0, <0.44.5
>=0.45.0-alpha.1, <0.45.0-alpha.5
Description
The NIP-44 v2 decryption path in the nostr crate contains a reachable panic
when processing a short or empty ciphertext. After the HMAC check passes and the
ciphertext is decrypted via ChaCha20, the code reads a 2‑byte unpadded‑length
prefix via buffer[0..2] without first verifying that the decrypted buffer
contains at least 2 bytes. A malicious sender who holds the symmetric
conversation key (e.g., a direct‑message sender) can craft a payload that
produces a 0 or 1‑byte decrypted buffer, causing an index‑out‑of‑bounds panic.
This can be triggered remotely through any relay that delivers the crafted
event to the victim's client, resulting in a denial of service. No key material,
plaintext, or memory corruption occurs.
The vulnerability is present in all versions from 0.26.0 up to 0.44.4
(inclusive) and in the alpha releases 0.45.0‑alpha.1 through 0.45.0‑alpha.4.
Versions 0.44.5 and 0.45.0‑alpha.5 contain the fix.
Credit
Discovered and responsibly disclosed by Muhammed Shekho (info@mhd-shekho.com, mhd-shekho.com).
Advisory available under CC0-1.0
license.