For security vulnerability reporting and our complete security policy, please see: https://github.com/nostrdevkit/guidelines
Security: nostrdevkit/nostr
Security
SECURITY.md
-
Wallet event parsers accept unauthenticated eventsGHSA-v2xx-q3jc-2r8w published
Aug 2, 2026 by yukibtcHigh -
NIP-98 authorization parsing permits resource exhaustionGHSA-f89m-394c-jfpm published
Aug 2, 2026 by yukibtcHigh -
Empty NIP-50 search filters can panicGHSA-739m-c885-58rq published
Aug 2, 2026 by yukibtcHigh -
NIP-44 v2 decryption permits resource exhaustionGHSA-9p75-m8cr-4h25 published
Aug 2, 2026 by yukibtcHigh -
NIP-04 parsing amplifies malformed ciphertext memory useGHSA-cjpx-rp36-fj8r published
Aug 2, 2026 by yukibtcModerate -
Debug output exposes NIP-46 and NIP-60 credentialsGHSA-j4ff-259j-7qjp published
Aug 2, 2026 by yukibtcModerate -
Relay authentication challenges can exhaust memoryGHSA-hwqm-xw2q-5hmc published
Aug 2, 2026 by yukibtcHigh -
Processing of unverified relay eventsGHSA-7863-gx29-2chr published
Aug 2, 2026 by yukibtcHigh -
Verification cache poisoning allows forged Nostr events to bypass signature validationGHSA-f96q-5f6p-v7cj published
Aug 1, 2026 by yukibtcHigh -
Remote Denial of Service via malformed NIP-04 IVGHSA-xg7c-246g-6qpv published
Jul 26, 2026 by yukibtcHigh
Learn more about advisories related to nostrdevkit/nostr in the GitHub Advisory Database