In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade nostr to version 0.44.5, 0.45.0-alpha.5 or higher.
Affected versions of this package are vulnerable to Uncaught Exception via the nostr::nips::nip44::decrypt, nostr::nips::nip44::decrypt_to_bytes, or nostr::nips::nip44::v2::decrypt_to_bytes functions. An attacker can cause a panic and terminate the process by sending a crafted payload that results in a decrypted buffer shorter than 2 bytes, leading to an out-of-bounds read.