nostr has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 6. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 8 prev 0
Products
- nostr 8
Worst active — by depth score
RUSTSEC-2026-0230High· 7.5Empty NIP-50 search filters can panic41RUSTSEC-2026-0229High· 7.5NIP-98 authorization parsing permits resource exhaustion41RUSTSEC-2026-0227High· 7.5NIP-44 v2 decryption permits resource exhaustion41RUSTSEC-2026-0226High· 7.5Wallet event parsers accept unauthenticated events41RUSTSEC-2026-0219High· 7.5Remote Denial of Service via malformed NIP-04 IV41
nostr vulnerabilities
CVEs affecting nostr, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
RUSTSEC-2026-0230High· 7.5Empty NIP-50 search filters can panic
Empty NIP-50 search filters can panic
RUSTSEC-2026-0229High· 7.5NIP-98 authorization parsing permits resource exhaustion
NIP-98 authorization parsing permits resource exhaustion
RUSTSEC-2026-0228Medium· 4.3NIP-04 parsing amplifies malformed ciphertext memory use
NIP-04 parsing amplifies malformed ciphertext memory use
RUSTSEC-2026-0227High· 7.5NIP-44 v2 decryption permits resource exhaustion
NIP-44 v2 decryption permits resource exhaustion
RUSTSEC-2026-0226High· 7.5Wallet event parsers accept unauthenticated events
Wallet event parsers accept unauthenticated events
RUSTSEC-2026-0225Medium· 5.5Debug output exposes NIP-46 and NIP-60 credentials
Debug output exposes NIP-46 and NIP-60 credentials
RUSTSEC-2026-0219High· 7.5Remote Denial of Service via malformed NIP-04 IV
Remote Denial of Service via malformed NIP-04 IV
RUSTSEC-2026-0216High· 7.5Remote Denial of Service via malformed NIP‑44 v2 payload
Remote Denial of Service via malformed NIP‑44 v2 payload