| Wallet RPC Restricted-Mode Policy Bypass |
Improper Authentication - Generic |
usagirabbit |
High |
2026-08-17 |
| Restricted RPC Policy Bypass on ZMQ JSON-RPC Allows Unauthenticated Remote Admin Actions |
Improper Authentication - Generic |
usagirabbit |
High |
2026-08-17 |
| `check_reserve_proof` counts duplicate entries: one output can inflate `total` |
Business Logic Errors |
bebensap |
Medium |
2026-08-05 |
| `check_reserve_proof` sums RingCT ECDH amounts without checking the output commitment |
Missing Required Cryptographic Step |
bebensap |
Medium |
2026-08-05 |
| wallet-rpc crash via malformed /gettransactions response (empty txs → vector::front() in check_tx_key / check_tx_proof) |
NULL Pointer Dereference |
bebensap |
High |
2026-08-05 |
| SpendProofV1 txid-substitution: get_spend_proof/check_spend_proof do not verify returned transaction hash |
Missing Required Cryptographic Step |
bebensap |
Medium |
2026-08-05 |
| wallet-rpc describe_transfer uses real_output_in_tx_index instead of real_output: cold-wallet pre-sign review shows wrong ring member |
Array Index Underflow |
bebensap |
Medium |
2026-08-05 |
| `set_daemon` wallet-rpc silently ignores `ssl_allowed_fingerprints` → pinning bypassed, wallet↔daemon MITM |
Improper Certificate Validation |
benisprlh |
High |
2026-08-05 |
| `relay_tx` wallet-rpc skips `--restricted-rpc` guard and lets any caller corrupt wallet state via attacker-controlled `pending_tx` |
Improper Access Control - Generic |
benisprlh |
Low |
2026-08-05 |
| ZMQ RPC Log Injection and Untrusted Payload Persistence |
CRLF Injection |
redlobsterzzz |
Medium |
2026-07-24 |
| Restricted RPC leaks alternative block hashes via /get_alt_blocks_hashes |
Improper Access Control - Generic |
int0ha_ |
Low |
2026-07-20 |
| Inverted ternary in peerlist_manager::filter() allows unlimited whitelist entries per host via different ports |
None supplied |
kklam32 |
No rating |
2026-06-29 |
| Remote node DOS |
Uncontrolled Resource Consumption |
xnbya |
Medium |
2026-06-29 |
| Critical Deadlock Vulnerability in Monero RPC Leading to Complete Node Paralysis |
Uncontrolled Resource Consumption |
rorkh |
Critical |
2026-05-06 |
| Connection Count Bug in Monero Node Enables Outbound Peer Reset Attack |
Privacy Violation |
yulge |
No rating |
2026-05-06 |
| Reported Denial of Service |
Uncontrolled Resource Consumption |
jehrenhofermagicgrants |
No rating |
2026-04-06 |
| Reported RPC Overflow |
Integer Overflow |
jehrenhofermagicgrants |
No rating |
2026-04-06 |
| Dynamic fee algorithm doesn't check for zero fee |
Uncontrolled Resource Consumption |
sech1 |
Low |
2025-05-23 |
| RPC service DOS |
Uncontrolled Resource Consumption |
ptrstr |
Medium |
2025-05-23 |
| Transactions in invalid blocks are kept in tx-pool without undergoing certain checks. |
None supplied |
boog900 |
No rating |
2025-04-23 |
| A peer can remotely fill the pending block queue to an extremely high size, with blocks that will never leave the queue. |
None supplied |
boog900 |
No rating |
2025-04-23 |
| Remote memory exhaustion in Epee RPC stack under zero Receive Window |
Uncontrolled Resource Consumption |
sagewilder2022 |
High |
2025-04-23 |
| Spamming highly nested JSON RPC requests cause node to disconnect from p2p network |
Uncontrolled Resource Consumption |
asurar0 |
No rating |
2025-04-23 |
| low-level p2p ping + tcp flooding leads to a remote crash in monerod |
None supplied |
padillac |
Critical |
2025-04-14 |
| [Monero wallet RPC] File precreation to file ownership and credentials leak |
Improper Access Control - Generic |
selmelc |
No rating |
2024-09-04 |
| Reentrancy attack in eth-monero atomic swap |
Improper Access Control - Generic |
farinavito123 |
No rating |
2023-04-20 |
| monerod JSON RPC server remote DoS |
Uncontrolled Resource Consumption |
m31007 |
Medium |
2022-09-12 |
| RPC call crashes node |
Uncontrolled Resource Consumption |
xfang |
High |
2022-08-20 |
| Misconfiguration in build environment allows DLL preloading attack |
None supplied |
nim4 |
Low |
2022-01-29 |
| DLL hijacking in Monero GUI for Windows 0.17.3.0 would allow an attacker to perform remote command execution |
Code Injection |
fukuyama |
Medium |
2021-12-30 |
| Array Index Underflow--http rpc |
Array Index Underflow |
minerscan |
High |
2021-10-11 |
| Hardware Wallets Do Not Check Unlock TIme |
Man-in-the-Middle |
thecharlatan |
Medium |
2021-09-12 |
| Unix time unlock_time values have dangerous validation rules enabling a number of exploits |
Business Logic Errors |
thecharlatan |
High |
2021-09-12 |
| Monero wallet password change is confirmed when not matching |
Unverified Password Change |
consistent-dream |
Low |
2020-03-11 |
| Potential linkage of public/private (anonymous) node addresses |
Information Disclosure |
ahook |
Low |
2020-03-11 |
| CVE-2019-13132 - libzmq 4.1 series is vulnerable |
Violation of Secure Design Principles |
evertonmelo |
Medium |
2019-11-18 |
| Monero Wallet Gui for Windows (Arbitrary Code Execution) |
Code Injection |
l00ph0le |
High |
2019-11-18 |
| Exploiting Network and Timing Side-Channels to Break Monero Receiver Anonymity |
None supplied |
ftramer |
Medium |
2019-11-15 |
| Locked_Transfer functional burning |
None supplied |
keejef |
High |
2019-07-09 |
| Excessive Resource Usage |
Uncontrolled Resource Consumption |
talko |
No rating |
2019-07-03 |
| CryptoNote: remote node DoS |
Uncontrolled Resource Consumption |
anonimal |
High |
2019-07-03 |
| Zero-amount miner TX + RingCT allows monero wallet to receive arbitrary amount of monero |
Resource Injection |
cutcoin |
Critical |
2019-07-03 |
| (remote) exabyte allocation via load_from_binary() (DoS) |
Uncontrolled Resource Consumption |
guido |
High |
2019-07-03 |
| Remote P2P DoS |
None supplied |
padillac |
Critical |
2019-07-03 |
| Remote Daemon RPC Attack |
None supplied |
padillac |
Medium |
2019-07-03 |
| Computing hash of crafted block leads to crash in tree_hash() |
Uncontrolled Resource Consumption |
guido |
High |
2019-07-03 |
| Monero can leak unitialized memory |
Information Disclosure |
guido |
Medium |
2019-07-02 |
| Potential use-after-free due to struct array_entry_t lacking an explicit copy constructor |
Use After Free |
guido |
Low |
2019-05-10 |
| RingCT malformed tx prevents target from being able to sweep balance |
Business Logic Errors |
organdonor1 |
Medium |
2019-04-20 |
| Unauthorized access of Monero wallet by an unprivileged process |
Improper Access Control - Generic |
thanhb |
High |
2019-04-03 |
| DoS for remote nodes using Slow Loris attack |
Uncontrolled Resource Consumption |
sobhraj_charles |
Medium |
2019-02-21 |
| Malicious get_random_rct_outs.bin rpc can cause a near-infinite loop |
Denial of Service |
ahook |
High |
2018-09-29 |
| Stack Overflow in JSON RPC Server |
Stack Overflow |
talko |
No rating |
2018-09-29 |
| Constant-time comparison is not always implemented; critical areas are vulnerable to key-timing attacks |
Missing Required Cryptographic Step |
anonimal |
Critical |
2018-08-06 |
| Trusted daemon check fails when proxied through torsocks or proxychains |
Privacy Violation |
equim |
Low |
2018-08-02 |
| Misreporting of received amount by show_transfers |
Business Logic Errors |
moneromooo |
High |
2018-08-02 |
| epee will accept an arbitrary amount of leading line-breaks in an http request |
Denial of Service |
ahook |
Low |
2018-08-02 |
| monerod can be disabled by a well-timed TCP reset packet |
Denial of Service |
ahook |
Medium |
2018-08-02 |
| A bug in the Monero wallet balance can enable theft from exchanges |
Business Logic Errors |
jagerman |
Critical |
2018-08-02 |
| Attcker can trick monero wallet into reporting it recived twice as much with alternative tx_keypubs |
Business Logic Errors |
phiren |
High |
2018-07-27 |
| forum.getmonero.org Shell upload |
Code Injection |
kaulse |
High |
2018-07-27 |
| Monero Website & Kovri on your policy are returning 404 not found. |
Business Logic Errors |
axolotl |
None |
2018-04-25 |
| TabNabbing issue (due to taget=_blank) |
None supplied |
ursa |
No rating |
2018-04-25 |
| Out-of-bounds read when importing corrupt blockchain with monero-blockchain-import |
Out-of-bounds Read |
ovrflow |
Low |
2018-04-25 |
| Buffer out of bound read in miniupnpc xml parser |
Buffer Over-read |
yukichen |
Low |
2018-04-25 |
| Monero GUI not linked with /DYNAMICBASE or hardening on windows, no ASLR |
None supplied |
flxflndy_ |
No rating |
2018-03-18 |
| Corrupt RPC responses from remote daemon nodes can lead to transaction tracing |
Privacy Violation |
monero-hax123 |
Medium |
2018-03-16 |
| remote access to localhost daemon, can issue jsonrpc commands |
Cross-Site Request Forgery (CSRF) |
bugbound |
Low |
2018-02-22 |
| Kovri: potential buffer over-read in garlic clove handling + I2NP message creation |
Information Disclosure |
aerodudrizzt |
High |
2017-12-05 |