RUSTSEC-2026-0231

Source
https://rustsec.org/advisories/RUSTSEC-2026-0231
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0231.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0231
Published
2026-08-01T12:00:00Z
Modified
2026-08-02T18:00:03.548661999Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Relay authentication challenges can exhaust memory
Details

The SDK forwarded every NIP-42 AUTH challenge received from a relay through an unbounded command queue. Challenge handling can wait for an asynchronous signer or user interaction, so receiving challenges was substantially faster than completing the corresponding authentication work.

A malicious relay could continuously send new challenges without authenticating or delivering valid events. Every value remained queued, causing memory use and pending signer operations to grow without a fixed limit until the client became unavailable. The issue does not allow the relay to forge a signature or learn the client's private key.

The SDK now coalesces pending challenges through a latest-value channel. NIP-42 makes an earlier challenge invalid when the relay sends a new one, so replacing pending work preserves the only challenge that can still be answered while keeping memory use bounded.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / nostr-relay-pool

Package

Name
nostr-relay-pool
View open source insights on deps.dev
Purl
pkg:cargo/nostr-relay-pool

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.44.3

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "arch": [],
        "os": [],
        "functions": []
    }
}

Database specific

cvss
"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0231.json"
categories
[
    "denial-of-service"
]
informational
null