RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0230

Empty NIP-50 search filters can panic

Reported
Issued
Package
nostr (crates.io)
Type
Vulnerability
Categories
Keywords
#nostr #nip50 #panic
References
CVSS Score
7.5 HIGH
CVSS Details
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality Impact
None
Integrity Impact
None
Availability Impact
High
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Patched
  • >=0.44.7

Description

The NIP-50 event-matching path searched event content with slice::windows(search.len()). An empty search string therefore called slice::windows(0), which always panics instead of returning a match result.

A remote client able to submit filters to an application using this matcher could trigger the panic with an empty NIP-50 search value. This includes clients querying an SDK local relay. Depending on the application's panic configuration and task isolation, the crafted filter could terminate request processing, a runtime worker, or the entire process, causing denial of service. No confidentiality or integrity impact is known.

Empty searches are now handled before the substring search, so the matcher returns a defined result without constructing a zero-sized window or panicking.

Advisory available under CC0-1.0 license.