
Cloud Vulnerability DB
A community-led vulnerabilities database
The NIP-44 v2 decryption path in the nostr crate contains a reachable panic
when processing a short or empty ciphertext. After the HMAC check passes and the
ciphertext is decrypted via ChaCha20, the code reads a 2‑byte unpadded‑length
prefix via buffer[0..2] without first verifying that the decrypted buffer
contains at least 2 bytes. A malicious sender who holds the symmetric
conversation key (e.g., a direct‑message sender) can craft a payload that
produces a 0 or 1‑byte decrypted buffer, causing an index‑out‑of‑bounds panic.
This can be triggered remotely through any relay that delivers the crafted
event to the victim's client, resulting in a denial of service. No key material,
plaintext, or memory corruption occurs.
The vulnerability is present in all versions from 0.26.0 up to 0.44.4
(inclusive) and in the alpha releases 0.45.0‑alpha.1 through 0.45.0‑alpha.4.
Versions 0.44.5 and 0.45.0‑alpha.5 contain the fix.
Discovered and responsibly disclosed by Muhammed Shekho (info@mhd-shekho.com, mhd-shekho.com).
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."