RUSTSEC-2026-0219
Remote Denial of Service via malformed NIP-04 IV
Details
The `nostr` crate did not validate the length of the initialization vector decoded from the `?iv=` portion of a NIP-04 encrypted message.
The decoded IV was converted from a byte slice to the 16-byte AES-CBC IV type using a conversion that asserts the slice length. As a result, an IV whose decoded length was not exactly 16 bytes caused a panic before ciphertext decryption. For example, `?iv=AAAA` decodes to a three-byte IV and triggers the panic.
Applications that decrypt untrusted NIP-04 content are affected. The issue is also reachable through NIP-47 (Nostr Wallet Connect), where response and notification events from a malicious or compromised wallet service are passed to NIP-04 decryption. If the panic is not isolated, a crafted event can terminate the application or disrupt message processing, causing a denial of service.
The issue does not affect confidentiality or integrity.
The flaw was corrected by converting the decoded IV to `[u8; 16]` using a checked conversion. Invalid IV lengths now return a `Malformed` error instead of panicking.
## Credit
Discovered and responsibly disclosed by **Muhammed Shekho** ([mhd-shekho.com](https://mhd-shekho.com)).
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0 Fixed in: 0.44.6 Upgrade nostr to 0.44.6 or newer (ecosystem crates.io).