🛡️ RUSTSEC-2026-0225 — nostr
Description
Debug output exposes NIP-46 and NIP-60 credentials
Several NIP-46 and NIP-60 types used derived Debug implementations even though
their fields contained credentials or decrypted application data. Formatting these
values exposed NIP-46 connection secrets and request parameters, as well as NIP-60
private keys, Cashu bearer proofs, and quote capability identifiers.
Applications commonly include Debug output in diagnostic logs, tracing spans, or
error reports. Anyone able to read those outputs could recover the disclosed
credentials and, depending on the value, impersonate a signer connection or spend
wallet tokens. The issue does not expose data unless an affected value is formatted
and the resulting output is made accessible.
The affected types now use custom Debug implementations that preserve variant and
non-sensitive structural information while replacing credentials, bearer values,
and plaintext fields with redaction markers. Serialization and protocol behavior are
unchanged.
How this vulnerability can be exploited
This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability none.
Affected software
RUSTSEC-2026-0225 is recorded against 1 package.
- nostr
Timeline and source
Published on 1 August 2026 and last revised on 2 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
crates.io (Package)
rustsec.org (Advisory)
github.com (Web)
github.com (Web)
Details
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| nostr | — | — |
References
Similar Threats
- Unknown RUSTSEC-2026-0237
- Unknown RUSTSEC-2026-0241
- Unknown RUSTSEC-2026-0243
- Unknown RUSTSEC-2026-0224
- Unknown RUSTSEC-2026-0226
More RUSTSEC 2026 advisories
Browse all of RUSTSEC 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by RUSTSEC-2026-0225?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against RUSTSEC-2026-0225 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.