RUSTSEC-2026-0228

Source
https://rustsec.org/advisories/RUSTSEC-2026-0228
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0228.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0228
Published
2026-08-01T12:00:00Z
Modified
2026-08-02T18:00:03.502761436Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS Calculator
Summary
NIP-04 parsing amplifies malformed ciphertext memory use
Details

The NIP-04 decryption parser split attacker-controlled content on every ?iv= separator and collected all resulting segments before checking that the message had the expected two parts. It also Base64-decoded the complete IV text before checking that it represented the required 16-byte AES-CBC IV.

A malicious sender could include a large number of separators or an oversized IV in an encrypted direct message. Applications that attempted to decrypt the message performed avoidable allocations proportional to the malformed input, with additional allocation amplification from the segment vector and Base64 output. This can consume memory and CPU in clients processing messages received through a relay. It does not weaken NIP-04 encryption or reveal plaintext or key material.

The parser now uses a single bounded split, rejects additional separators, and validates the 24-byte encoded IV length before Base64 decoding. Malformed inputs are returned as errors without allocating for every separator or decoding an arbitrarily large IV.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / nostr

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.44.7

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "functions": [],
        "os": [],
        "arch": []
    }
}

Database specific

source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0228.json"
informational
null
cvss
"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
categories
[
    "denial-of-service"
]