Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.
Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.
51/100 average clarity
20Strong · 80–100
123Adequate · 60–79
534Thin · 40–59
66Opaque · 0–39
14security candidates with opaque commit messaging
This Monero wallet update fixes a bookkeeping bug. When a wallet imported a list of its owned outputs and that list was smaller than a previous import, internal lookup maps (key images and public keys) could still point to entries that no …
Internal index/cache consistency fix in wallet output handlingPrevents out-of-range references after transfer list resizeAdds defensive repair on wallet cache load for unrefreshed wallets
This commit simplifies how Monero's simplewallet decides whether a payment ID is a real encrypted ID or a dummy placeholder. Previously, the wallet checked both the payment ID value and whether any destination was an integrated address, an…
Removal of a CHECK_AND_ASSERT_MES consistency check between destination flags and payment ID valueChange from dual-factor classification (address type + payload) to payload-only classificationPotential for previously rejected transactions to be accepted if the old check was overly strict
This Monero wallet patch cleans up internal lookup tables (key-image and public-key indexes) when the list of owned transaction outputs is shrunk, for example during an output import. Without the cleanup, those indexes could point to entri…
Out-of-bounds index retained in wallet lookup maps after container shrinkPotential wallet crash or incorrect spend selection due to stale key-image / public-key mappingRepair-on-load for legacy wallet caches that predate the fix
This small change removes a consistency check in Monero's command-line wallet when loading a saved transaction. Previously, the wallet verified that a 'dummy' payment ID label matched a special zero-value payment ID. Now it labels the paym…
Removal of a CHECK_AND_ASSERT_MES consistency checkRemoval of integrated-address validation for payment ID classificationChange in UI/labeling logic for loaded transactions
This commit updates Monero's built-in blockchain checkpoints to match the v0.18.5.3 release. Checkpoints are hard-coded reference points that help nodes quickly verify they are following the correct chain and resist certain attacks. The ch…
Hard-coded blockchain checkpoint data updated to a newer height/hashExpected compiled-in block hashes digest changedNo new code paths, cryptographic changes, or bug fixes visible in the diff
This is a small code fix in Monero's wallet that keeps the recorded breakdown of received amounts consistent when a transaction output is 'burnt' (replaced or spent as part of a transaction the wallet is processing). The change adds a chec…
Defensive consistency check added (THROW_WALLET_EXCEPTION_IF)Fixes internal accounting of received output amountsNo explicit security claim in commit or supplied references
This patch fixes a spot in the Monero wallet where an untrusted remote server (daemon) could supply a misleading 'status' field. Previously, the wallet used that raw status directly in its error handling, which could potentially make a mal…
Untrusted input from remote daemon used in error-handling pathMissing trust check on daemon-reported RPC statusSingle-call-site hardening patch
This commit adds two new read-only options to the wallet's remote procedure call (RPC) interface so users can request their public view key and public spend key. Public keys are meant to be shared openly and are not secrets, so exposing th…
This commit only updates a submodule pointer for the external polyseed library from one commit hash to another. The actual code changes inside the submodule are not shown in the diff, and no public references were supplied. There is no vis…
This patch fixes a size-limit accounting bug in Monero's built-in HTTP server. When a client sends multiple HTTP requests back-to-back on the same connection (pipelining), leftover buffered data from the next request was not being counted …
Request size limit bypass via pipelined HTTP cachingDenial-of-service / memory pressure potential from oversized requestsFix in low-level network protocol handler
This patch fixes a privacy leak in Monero's wallet RPC server. Previously, the --no-dns flag was ignored when no wallet was loaded, so the validate_address RPC call could still perform a DNS lookup (OpenAlias) even though the user had expl…
Privacy leak: RPC ignored --no-dns when no wallet loadedDNS lookup performed despite explicit user opt-outOpenAlias resolution could disclose queried addresses/aliases to DNS resolvers
This commit adds cleanup of three additional memory buffers in Monero's seed-phrase key-stretching code. Before the change, leftover copies of intermediate secrets could remain in stack memory after the function finished. An attacker who c…
Sensitive intermediate key material left in stack memory after function returnUse of sodium_memzero to clear cryptographic buffersPBKDF2 implementation handling mnemonic-derived secrets
This update improves the Monero wallet's command that connects to a network node (daemon). It lets users supply a username/password and a proxy address when switching daemons, and it replaces an older one-step connection method with a newe…
Added mutex lock in wallet2::set_proxy to protect concurrent access to proxy and HTTP client stateset_daemon now passes RPC login credentials and proxy settings through the proper wallet2::set_daemon APITrust heuristic changed to only auto-trust local daemons when no proxy is in use
This change alters how Monero creates a view-only wallet copy. Previously, the code exported outputs using a method that could strip some metadata. Now it copies the full internal transfer records directly, then wipes and clears the multi-…
Sensitive field sanitization before export (memwipe + clear of m_multisig_k)Change in data export path for view-only wallet creationPreservation of 'complete output metadata' implying previous path was incomplete
This Monero update hardens how public keys and transaction pubkeys are handled. It moves a low-level 'torsion clearing' routine into the core crypto library, adds checks that wallet/destination addresses are valid points on the main subgro…
Adds main-subgroup membership validation for public address keys (spend/view)Normalizes transaction public keys before use in payment-ID decryption and tx proofsMoves torsion-clearing primitive into core crypto layer to ensure consistent behavior
This Monero update fixes a networking bug where the server could accidentally block all of its worker threads while waiting for slow clients to accept data. If all workers became stuck this way, the node could stop processing any network t…
Removal of blocking condition-variable wait in network send pathFail-fast on send-queue overflow instead of parking worker threadsHTTP handler now propagates send failures and enters error state
This Monero wallet patch adds stronger safety checks when a wallet prepares, signs, or loads multi-step transactions (unsigned transactions, multisig transactions, and cold-device transactions). It verifies that money going into the transa…
Adds duplicate-input detection across transaction setsAdds destination address type consistency checksAdds uint64 overflow guard for summed input amounts
This Monero update makes the network layer clean up leftover block download records when a peer connection fails or is rejected. Previously, rejected or disconnected peers could leave stale block spans in a queue, which might cause the nod…
Denial-of-service resistance: stale block spans from malicious or faulty peers could prevent a node from obtaining valid blocksState cleanup on peer disconnection/rejectionNo authentication or memory-safety bug evident in diff
This small patch fixes a bug in the Monero wallet where, if an output had already been scanned once, the wallet would return early without clearing an error flag. In rare cases this could leave a stale 'error' state attached to a transacti…
Stale error-state propagation in wallet scanning logicMissing reset of tx_scan_info.error on cached/short-circuit code pathPotential for incorrect received-payment or scan-failure reporting
This change fixes a binary search in the Monero wallet that previously could loop forever or behave incorrectly if something went wrong. The old code used an unbounded 'while (true)' loop and a midpoint calculation that could overflow. The…
Unbounded loop replaced with bounded iterationInteger overflow mitigation in midpoint calculationDefensive error handling added for search failure
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Low 34/100
This commit refactors how Monero's blockchain code builds a lookup table used when checking incoming blocks. It replaces a slower, manual scan through offsets with a sorted binary search, and removes duplicate amount handling. The change appears to be a performance and correctness cleanup rather than a clear security fix, but the old code's linear search and duplicate-amount logic could theoretically hide or mishandle edge cases in block validation.
Security candidateOptimized handle_notify_new_transactions's duplicate tx check - Check sha256 digests instead of full blobs (much less memory used) - Replace `find->insert` sequence with a single `insert` - 2x fewer hashset accesses - Preallocate the required size for the hashset (no full-table rehashes)by SChernykh · 330062a0 · Jun 29, 2026 · 1 fileMessage 73 · AdequateInformational 19Details
Commit message · SChernykh
Optimized handle_notify_new_transactions's duplicate tx check - Check sha256 digests instead of full blobs (much less memory used) - Replace `find->insert` sequence with a single `insert` - 2x fewer hashset accesses - Preallocate the required size for the hashset (no full-table rehashes)
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive pathparser or protocol path
AI analysis · Informational 19/100
This commit is a performance optimization in Monero's transaction-processing code. It changes how the node detects duplicate transactions sent by a peer: instead of comparing the entire transaction data (which uses lots of memory), it compares small SHA-256 fingerprints. It also streamlines how those fingerprints are stored. There is no direct evidence this fixes a security bug, but it removes a memory-pressure path and hardens duplicate detection against subtle blob differences.
AI review queuedwallet2: avoid linear scans in pool state updatesby selsta · d40944c4 · Jun 28, 2026 · 2 filesMessage 45 · ThinInformational 19Details
Commit message · selsta
wallet2: avoid linear scans in pool state updates
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100
This commit is a performance optimization in the Monero wallet. It replaces repeated linear list scans with hash-set lookups when checking which transactions are in the memory pool. The change should make wallet refresh faster when there are many pending transactions, but it does not appear to fix a security vulnerability or change behavior in a way that is directly exploitable.
Security candidateFix spelling typos in comments and string literalsby Thomas · fecef767 · Jun 27, 2026 · 32 filesMessage 50 · ThinInformational 15Details
Commit message · Thomas
Fix spelling typos in comments and string literals
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet pathparser or protocol path
AI analysis · Informational 15/100
This commit only fixes spelling mistakes in comments, documentation, and user-facing error/log strings. No program logic, calculations, or security behavior was changed. It is not a security fix and cannot be exploited.
AI review queuedwallet2: remove unused pool tx removed callbackby selsta · b1f45614 · Jun 26, 2026 · 2 filesMessage 68 · AdequateInformational 16Details
Commit message · selsta
wallet2: remove unused pool tx removed callback
on_pool_tx_removed has no implementation beyond the empty default callback and is not wired through the wallet API layer.
The only call site passed txid after erasing the payment entry that owned it, leaving a dangling reference.
68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100
This commit removes a leftover wallet callback function that did nothing useful. The callback was called after a transaction record had already been deleted, so the transaction ID it received was technically invalid (a 'dangling reference'). Because the callback had no real implementation and was not exposed through the public wallet API, this appears to be a cleanup of dead code rather than a fix for an actively exploitable bug. The main risk is avoiding undefined behavior if someone later tried to use that invalid reference.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidenceprivacy or spend-authorization protocol
AI analysis · Informational 15/100
This commit only adds new software tests (fuzz tests) for Monero's CLSAG ring signature verification code. It does not change any production code that handles transactions, wallets, or network data. Fuzz tests feed random or crafted data to a function to check it behaves safely, but the tests themselves are not a vulnerability or a fix. There is no indication this commit addresses a known security bug.
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
fuzzing or regression evidenceauthentication path
AI analysis · Informational 16/100
This commit updates a Monero fuzz test that feeds random or crafted data to the wallet's cold-output import code. It only changes test files and test code; no production wallet or node code is modified. The change makes the fuzzer use the newer, safer import path (import_outputs_from_str) and adds a testnet wallet setup. On its own, this is a test-harness cleanup, not a fix for a live security bug.
p2p: restore safe sync mode when target height drops
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathparser or protocol path
AI analysis · Low 46/100
This small patch changes Monero's peer-to-peer sync logic so that when the node's estimated target blockchain height suddenly drops, it re-enables 'safe sync mode' if the target is now very close to the node's current height. Safe sync mode is a more conservative way of downloading and verifying blocks. The change is defensive: without it, a node might stay in a faster but less safe sync mode even when the network no longer appears to be far ahead, which could make it more vulnerable to a malicious peer manipulating its view of the chain height. The commit message does not call this a security fix, and no independent researcher is credited.
AI review queuedwallet: store fee for not_enough_{unlocked_,}balanceby tobtoht · 06221f20 · Jun 24, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · tobtoht
wallet: store fee for not_enough_{unlocked_,}balance
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit only adds a 'fee' field to two existing wallet error types (not_enough_unlocked_money and not_enough_money). It does not change how transactions are validated, how fees are calculated, or how money is handled. It simply lets the wallet remember and report what fee was involved when an error about insufficient balance occurs. There is no security issue visible in this change.
AI review queuedtests: remove dead transactions_generation_from_blockchainby Thomas · 8a744a63 · Jun 23, 2026 · 3 filesMessage 73 · AdequateInformational 15Details
Commit message · Thomas
tests: remove dead transactions_generation_from_blockchain
Functional test commented out since 2014 (296ae46ed); never #included or called (main.cpp only runs transactions_flow_test).
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit simply deletes an old, unused test file and its header. The code being removed was entirely commented out since 2014, was never compiled into the test program, and was never run. It has no effect on the live Monero software or its users.
Security candidatecommon: remove unused data_cache.hby Thomas · b5136b1a · Jun 23, 2026 · 2 filesMessage 60 · AdequateInformational 15Details
Commit message · Thomas
common: remove unused data_cache.h
Dead since 40eb82873 (2025-10) moved verRct caching into the mempool; only a stale #include remained in blockchain.cpp.
60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit simply deletes an unused header file and removes its leftover include statement. It is a cleanup change with no functional or security effect on the running software.
AI review queuedhttp: parse server Content-Length strictlyby alhudz · 07f7c752 · Jun 23, 2026 · 2 filesMessage 45 · ThinModerate 51Details
Commit message · alhudz
http: parse server Content-Length strictly
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Moderate 51/100
This commit tightens how Monero's built-in HTTP server reads the 'Content-Length' header. Previously, the server would accept malformed values like '5abc' or '0x10' and silently use only the leading digits as the body length. Now it rejects the whole value unless it is a plain number. This kind of lenient parsing can cause request smuggling or desynchronization between the server and other HTTP components, which attackers can sometimes exploit to bypass security controls or poison caches.
AI review queuedsimplewallet: fix some more typosby jpk68 · 14e17537 · Jun 22, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · jpk68
simplewallet: fix some more typos
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit fixes three spelling mistakes in user-facing error messages inside Monero's command-line wallet. There are no code logic changes, no security fixes, and no functional impact.
Security candidatecmake: set message mode everywhereby tobtoht · 9ed0a114 · Jun 21, 2026 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · tobtoht
cmake: set message mode everywhere
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet pathdocumentation-only discount
AI analysis · Informational 15/100
This commit only changes two CMake build messages from plain 'message(...)' to 'message(STATUS ...)'. That is a cosmetic/logging change: it tells CMake to print these lines as informational status messages instead of bare output. It does not change any compiled code, cryptographic logic, wallet behavior, or security boundary.
AI review queuedhttp: share deterministic header field parserby selsta · 389f3660 · Jun 21, 2026 · 4 filesMessage 45 · ThinModerate 66Details
Commit message · selsta
http: share deterministic header field parser
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Moderate 66/100
This commit replaces a complex regular-expression-based HTTP header parser with a single, stricter, hand-written parser shared between the client and server code. The old parser could silently accept malformed or ambiguous headers, which in HTTP can lead to security problems such as request smuggling, cache poisoning, or unexpected behavior. The new parser rejects headers that do not follow a well-defined format and validates the characters allowed in header names. It also adds many tests that demonstrate malformed headers are now rejected. The commit itself does not describe this as a security fix, but the change clearly reduces attack surface in the way Monero's HTTP stack processes incoming and outgoing headers.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit only adds standard copyright and license notice blocks to the top of three wallet source files. It does not change any program logic, data handling, or user-facing behavior, so it has no security impact on the Monero software itself.
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolcryptography-sensitive path
AI analysis · Low 29/100
This commit changes how Monero reads payment IDs embedded in transaction data. Previously, the code used a type-casting pointer trick to read the bytes; now it uses memcpy, which is the safer, standard way to copy raw bytes. The change is defensive and reduces the risk of subtle memory alignment or aliasing problems, but the commit itself does not claim to fix an active security bug.
AI review queuedwallet2: avoid std::out_of_range on a truncated tx set blobby Thomas · 36bb2d0e · Jun 20, 2026 · 1 fileMessage 73 · AdequateLow 28Details
Commit message · Thomas
wallet2: avoid std::out_of_range on a truncated tx set blob
parse_unsigned_tx_from_str() and parse_tx_from_str() strip the magic, then read the version byte and call s.substr(1) without checking a version byte follows. A blob equal to just the magic leaves an empty remainder, so s.substr(1) throws std::out_of_range instead of the function returning false. Require magic + a version byte first.
73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 28/100
This commit fixes a minor crash bug in Monero's wallet code. When the wallet tried to read a transaction data blob that contained only the file-type 'magic' header and nothing else, it would throw an uncaught out-of-range exception instead of cleanly reporting 'bad data.' The patch makes the wallet check that at least one byte follows the magic before reading it, turning the crash into a normal error return.
Security candidateFix spelling typosby Thomas · 02db831d · Jun 18, 2026 · 35 filesMessage 28 · OpaqueInformational 15Details
Commit message · Thomas
Fix spelling typos
28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathsigning or wallet pathparser or protocol path
AI analysis · Informational 15/100
This commit is a routine cleanup that fixes spelling mistakes and typos across comments, error messages, variable names, and documentation strings. None of the changes alter program logic, data handling, or security behavior. The only file rename (instanciations.cpp → instantiations.cpp) is a spelling correction, and the CMakeLists.txt reference is updated to match. There is no security impact.
This commit fixes a single-word typo in a documentation file, changing 'Bitcoin' to 'Monero' in a sentence describing the dependency build system. It has no effect on program code, behavior, or security.
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100
This commit simply deletes a helper function called power_integral that was not being used anywhere in the code. It is a routine cleanup with no visible security effect.
AI review queuedwallet2: read multisig restore fields with memcpy in generateby alhudz · 6ad3dc08 · Jun 15, 2026 · 1 fileMessage 50 · ThinLow 48Details
Commit message · alhudz
wallet2: read multisig restore fields with memcpy in generate
50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 48/100
This commit changes how a Monero wallet reads sensitive key data from a multisig restore string. Previously, the code directly cast a pointer to the data buffer and read keys as if they were already in the correct structure. Now it uses memcpy, which is the safer, standard way to copy raw bytes into typed variables. The main practical concern is avoiding undefined behavior from unaligned or improperly typed memory access, especially for secret key types that may have stricter alignment requirements. It is a hardening fix rather than a clear-cut remote exploit.
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 61/100
This change makes the Monero wallet refuse to build transactions if the list of RingCT output counts it gets from a daemon is not in ascending order. A non-monotonic (out-of-order or decreasing) distribution could indicate a misbehaving or malicious daemon trying to trick the wallet into selecting invalid or non-existent outputs, which might lead to failed transactions or privacy/funds issues. The patch is a defensive check, but it is small and does not by itself prove an active attack is possible.
AI review queuedwallet: wallet args take argv[] as constby jeffro256 · e9a8a268 · Jun 15, 2026 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · jeffro256
wallet: wallet args take argv[] as const
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100
This commit changes the wallet's command-line argument handling so the program's input arguments are treated as read-only (const). It is a code-quality and type-safety improvement, not a security fix. There is no indication it prevents or fixes any exploit.
AI review queuedsimplewallet: misc safety/correctness fixesby jpk68 · 6aba4596 · Jun 12, 2026 · 1 fileMessage 45 · ThinLow 34Details
Commit message · jpk68
simplewallet: misc safety/correctness fixes
45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100
This commit fixes several crash bugs and one possible underflow bug in Monero's command-line wallet (simplewallet). Most changes add null-pointer checks before using the wallet object, preventing the program from crashing if a user runs commands before a wallet is loaded. One change prevents a subtraction from going below zero when computing the number of 'fake' transaction outputs. Another change removes an incorrect argument-count check in the device-name command. The commit is described by its author as general safety/correctness fixes, not as a security patch.