VDB
KO
HIGH 7.5

RUSTSEC-2026-0219

Remote Denial of Service via malformed NIP-04 IV

Details

The `nostr` crate did not validate the length of the initialization vector decoded from the `?iv=` portion of a NIP-04 encrypted message.

The decoded IV was converted from a byte slice to the 16-byte AES-CBC IV type using a conversion that asserts the slice length. As a result, an IV whose decoded length was not exactly 16 bytes caused a panic before ciphertext decryption. For example, `?iv=AAAA` decodes to a three-byte IV and triggers the panic.

Applications that decrypt untrusted NIP-04 content are affected. The issue is also reachable through NIP-47 (Nostr Wallet Connect), where response and notification events from a malicious or compromised wallet service are passed to NIP-04 decryption. If the panic is not isolated, a crafted event can terminate the application or disrupt message processing, causing a denial of service.

The issue does not affect confidentiality or integrity.

The flaw was corrected by converting the decoded IV to `[u8; 16]` using a checked conversion. Invalid IV lengths now return a `Malformed` error instead of panicking.

## Credit

Discovered and responsibly disclosed by **Muhammed Shekho** ([mhd-shekho.com](https://mhd-shekho.com)).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / nostr
Introduced in: 0.0.0-0 Fixed in: 0.44.6

Upgrade nostr to 0.44.6 or newer (ecosystem crates.io).

References