RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0219

Remote Denial of Service via malformed NIP-04 IV

Reported
Issued
Package
nostr (crates.io)
Type
Vulnerability
Categories
Keywords
#panic #nip04 #nip47 #nwc
References
CVSS Score
7.5 HIGH
CVSS Details
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality Impact
None
Integrity Impact
None
Availability Impact
High
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Patched
  • >=0.44.6, <0.45.0-alpha.1
  • >=0.45.0-alpha.6
Affected Functions
Version
nostr::nips::nip04::decrypt
  • >=0.1.5
nostr::nips::nip04::decrypt_to_bytes
  • >=0.26.0

Description

The nostr crate did not validate the length of the initialization vector decoded from the ?iv= portion of a NIP-04 encrypted message.

The decoded IV was converted from a byte slice to the 16-byte AES-CBC IV type using a conversion that asserts the slice length. As a result, an IV whose decoded length was not exactly 16 bytes caused a panic before ciphertext decryption. For example, ?iv=AAAA decodes to a three-byte IV and triggers the panic.

Applications that decrypt untrusted NIP-04 content are affected. The issue is also reachable through NIP-47 (Nostr Wallet Connect), where response and notification events from a malicious or compromised wallet service are passed to NIP-04 decryption. If the panic is not isolated, a crafted event can terminate the application or disrupt message processing, causing a denial of service.

The issue does not affect confidentiality or integrity.

The flaw was corrected by converting the decoded IV to [u8; 16] using a checked conversion. Invalid IV lengths now return a Malformed error instead of panicking.

Credit

Discovered and responsibly disclosed by Muhammed Shekho (mhd-shekho.com).

Advisory available under CC0-1.0 license.