nostr vulnerabilities
CVEs whose affected-version data names the nostr package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
8 CVEsRSS
RUSTSEC-2026-0230High· 7.5Empty NIP-50 search filters can panic
Empty NIP-50 search filters can panic
▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0229High· 7.5NIP-98 authorization parsing permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0228Medium· 4.3NIP-04 parsing amplifies malformed ciphertext memory use
NIP-04 parsing amplifies malformed ciphertext memory use
▾ Sunlitnostr · nostrvia OSV
RUSTSEC-2026-0227High· 7.5NIP-44 v2 decryption permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0226High· 7.5Wallet event parsers accept unauthenticated events
Wallet event parsers accept unauthenticated events
▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0225Medium· 5.5Debug output exposes NIP-46 and NIP-60 credentials
Debug output exposes NIP-46 and NIP-60 credentials
▾ Sunlitnostr · nostrvia OSV
RUSTSEC-2026-0219High· 7.5Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP-04 IV
▾ Twilightnostr · nostrvia OSV
RUSTSEC-2026-0216High· 7.5Remote Denial of Service via malformed NIP‑44 v2 payload
Remote Denial of Service via malformed NIP‑44 v2 payload
▾ Twilightnostr · nostrvia OSV