
Cloud Vulnerability DB
A community-led vulnerabilities database
The SDK forwarded every NIP-42 AUTH challenge received from a relay through an
unbounded command queue. Challenge handling can wait for an asynchronous signer or
user interaction, so receiving challenges was substantially faster than completing
the corresponding authentication work.
A malicious relay could continuously send new challenges without authenticating or
delivering valid events. Every value remained queued, causing memory use and pending
signer operations to grow without a fixed limit until the client became unavailable.
The issue does not allow the relay to forge a signature or learn the client's private
key.
The SDK now coalesces pending challenges through a latest-value channel. NIP-42 makes
an earlier challenge invalid when the relay sends a new one, so replacing pending
work preserves the only challenge that can still be answered while keeping memory
use bounded.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."