{"id":"RUSTSEC-2026-0216","title":"Remote Denial of Service via malformed NIP‑44 v2 payload","summary":"Remote Denial of Service via malformed NIP‑44 v2 payload","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"nostr","product":"nostr","ecosystem":"rust","affected":["nostr >= 0.45.0-alpha.1, < 0.45.0-alpha.5"],"patched":["nostr 0.45.0-alpha.5"],"published":"2026-07-25","updated":"2026-07-27","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0216","references":[{"url":"https://crates.io/crates/nostr"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0216.html"},{"url":"https://github.com/nostrdevkit/nostr/commit/73bdd677b872641d57a2ebcc5afc23ee0e5f0d2d"}],"tags":["osv","rust"],"ingestedAt":"2026-07-27T19:08:56.156Z","slug":"RUSTSEC-2026-0216","body":"## Overview\n\nThe NIP-44 v2 decryption path in the `nostr` crate contains a reachable panic\nwhen processing a short or empty ciphertext. After the HMAC check passes and the\nciphertext is decrypted via ChaCha20, the code reads a 2‑byte unpadded‑length\nprefix via `buffer[0..2]` without first verifying that the decrypted buffer\ncontains at least 2 bytes. A malicious sender who holds the symmetric\nconversation key (e.g., a direct‑message sender) can craft a payload that\nproduces a 0 or 1‑byte decrypted buffer, causing an index‑out‑of‑bounds panic.\nThis can be triggered remotely through any relay that delivers the crafted\nevent to the victim's client, resulting in a denial of service. No key material,\nplaintext, or memory corruption occurs.\n\nThe vulnerability is present in all versions from `0.26.0` up to `0.44.4`\n(inclusive) and in the alpha releases `0.45.0‑alpha.1` through `0.45.0‑alpha.4`.\nVersions `0.44.5` and `0.45.0‑alpha.5` contain the fix.\n\n## Credit\n\nDiscovered and responsibly disclosed by **Muhammed Shekho** (info@mhd-shekho.com, [mhd-shekho.com](https://mhd-shekho.com)).\n\n## Affected packages\n\n- `nostr >= 0.45.0-alpha.1, < 0.45.0-alpha.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nostr 0.45.0-alpha.5`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}