RUSTSEC-2026-0224

Source
https://rustsec.org/advisories/RUSTSEC-2026-0224
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0224.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0224
Aliases
  • GHSA-f96q-5f6p-v7cj
Published
2026-08-01T12:00:00Z
Modified
2026-08-01T15:15:03.610976353Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Verification cache poisoning allows forged Nostr events to bypass signature validation
Details

The nostr-relay-pool crate cached the result of event signature verification before the check was actually performed. Because the entry was inserted unconditionally, a first delivery whose signature failed was still recorded in the cache. A subsequent delivery of the same event (identical ID, but with a forged signature) would then hit the cache, causing signature verification to be skipped entirely. The forged event was passed on to NostrDatabase::save_event() as if it had been validated.

Applications that connect to untrusted or compromised Nostr relays and persist received events are vulnerable. An attacker can inject arbitrary events without a valid signature into the application's trusted database, enabling impersonation of any public key or corruption of application state derived from stored events.

The issue does not compromise confidentiality or availability. It solely undermines the integrity of stored event data.

The fix, released in version 0.44.2, moves the cache insertion to occur only after a successful signature verification, so that failed attempts never create a cache entry.

Credit

Discovered and reported by Ali Al-Sorehi

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / nostr-relay-pool

Package

Name
nostr-relay-pool
View open source insights on deps.dev
Purl
pkg:cargo/nostr-relay-pool

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.44.2

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "functions": [],
        "arch": [],
        "os": []
    }
}

Database specific

categories
[
    "crypto-failure"
]
cvss
"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0224.json"