Skip to content

Conversation

@sstone
Copy link
Member

@sstone sstone commented Aug 18, 2025

Reported in #157.
When decoding a bech32 string, we did not properly check for invalid characters (i.e. not in the bech32 character set) in the data part. Instead we failed later with an Index 5 out of bounds for length 5 error during checksum verification when decoding BOLT11 invoices, and don't fail at all when decoding offers (which bypasses checksum verification).

We did not properly check for invalid characters (i.e. not in the bech32 character set) in the data part.
@sstone sstone requested a review from t-bast August 18, 2025 16:19
Copy link
Member

@t-bast t-bast left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch!

@sstone sstone merged commit 74641a7 into master Aug 19, 2025
2 checks passed
@sstone sstone deleted the bech32-invalid-char branch August 19, 2025 08:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants