---
id: RUSTSEC-2026-0219
title: Remote Denial of Service via malformed NIP-04 IV
summary: Remote Denial of Service via malformed NIP-04 IV
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: nostr
product: nostr
ecosystem: rust
affected:
  - 'nostr >= 0.45.0-alpha.1, < 0.45.0-alpha.6'
patched:
  - nostr 0.45.0-alpha.6
published: '2026-07-26'
updated: '2026-07-29'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0219'
references:
  - url: 'https://crates.io/crates/nostr'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0219.html'
  - url: >-
      https://github.com/nostrdevkit/nostr/commit/b24619346f666d08ef7fefe27f033b8bc871697f
tags:
  - osv
  - rust
ingestedAt: '2026-07-29T19:09:38.057Z'
---

## Overview

The `nostr` crate did not validate the length of the initialization vector
decoded from the `?iv=` portion of a NIP-04 encrypted message.

The decoded IV was converted from a byte slice to the 16-byte AES-CBC IV type
using a conversion that asserts the slice length. As a result, an IV whose
decoded length was not exactly 16 bytes caused a panic before ciphertext
decryption. For example, `?iv=AAAA` decodes to a three-byte IV and triggers the
panic.

Applications that decrypt untrusted NIP-04 content are affected. The issue is
also reachable through NIP-47 (Nostr Wallet Connect), where response and
notification events from a malicious or compromised wallet service are passed
to NIP-04 decryption. If the panic is not isolated, a crafted event can terminate
the application or disrupt message processing, causing a denial of service.

The issue does not affect confidentiality or integrity.

The flaw was corrected by converting the decoded IV to `[u8; 16]` using a
checked conversion. Invalid IV lengths now return a `Malformed` error instead of
panicking.

## Credit

Discovered and responsibly disclosed by **Muhammed Shekho** ([mhd-shekho.com](https://mhd-shekho.com)).

## Affected packages

- `nostr >= 0.45.0-alpha.1, < 0.45.0-alpha.6`

## Remediation

Upgrade to a patched release:

- `nostr 0.45.0-alpha.6`
