XMR
← All projectsMonero Project

Monero

Reference Monero node, command-line wallet, consensus, networking, and cryptographic protocol implementation.

Cryptographic librariesMoneroNode implementationsPrivacy protocolsNormal
Repository coverage

743 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

219security candidates228second-pass queue447AI analyses
113commits · 30 days
235commits · 60 days
644commits · 180 days
742commits · 365 days
Backfill bands
Sep 27 → Mar 3192 seen34 candidatesComplete
Mar 31 → Jul 29369 seen101 candidatesComplete
Jul 29 → Aug 28128 seen36 candidatesComplete
Aug 28 → Sep 2788 seen21 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

51/100 average clarity
20Strong · 80–100
123Adequate · 60–79
534Thin · 40–59
66Opaque · 0–39
14security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
jeffro256633850257
koe313259
tobtoht1823283150
Cole Munz424177
Masamune222164
SNeedlewoods805152
selsta1744997051
j-berman432934058
jpk68881452046
Samy371023048
Thomas271015057
SChernykh1188062
Analysis record

Published AI watches

Last scanned 1 minute ago

Low 42 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11462

This Monero wallet update fixes a bookkeeping bug. When a wallet imported a list of its owned outputs and that list was smaller than a previous import, internal lookup maps (key images and public keys) could still point to entries that no …

Internal index/cache consistency fix in wallet output handlingPrevents out-of-range references after transfer list resizeAdds defensive repair on wallet cache load for unrefreshed wallets
160e2150by tobtoht+29−02 files
No security note in commit
Low 26 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11460

This commit simplifies how Monero's simplewallet decides whether a payment ID is a real encrypted ID or a dummy placeholder. Previously, the wallet checked both the payment ID value and whether any destination was an integrated address, an…

Removal of a CHECK_AND_ASSERT_MES consistency check between destination flags and payment ID valueChange from dual-factor classification (address type + payload) to payload-only classificationPotential for previously rejected transactions to be accepted if the old check was overly strict
4b84712eby tobtoht+1−91 file
No security note in commit
Low 42 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

wallet2: trim stale transfer maps after output imports

This Monero wallet patch cleans up internal lookup tables (key-image and public-key indexes) when the list of owned transaction outputs is shrunk, for example during an output import. Without the cleanup, those indexes could point to entri…

Out-of-bounds index retained in wallet lookup maps after container shrinkPotential wallet crash or incorrect spend selection due to stale key-image / public-key mappingRepair-on-load for legacy wallet caches that predate the fix
80f75eaaby selsta+29−02 files
No security note in commit
Low 25 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

simplewallet: classify payment IDs by their payload

This small change removes a consistency check in Monero's command-line wallet when loading a saved transaction. Previously, the wallet verified that a 'dummy' payment ID label matched a special zero-value payment ID. Now it labels the paym…

Removal of a CHECK_AND_ASSERT_MES consistency checkRemoval of integrated-address validation for payment ID classificationChange in UI/labeling logic for loaded transactions
5937d5cfby selsta+1−91 file
No security note in commit
Informational 22 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11161

This commit updates Monero's built-in blockchain checkpoints to match the v0.18.5.3 release. Checkpoints are hard-coded reference points that help nodes quickly verify they are following the correct chain and resist certain attacks. The ch…

Hard-coded blockchain checkpoint data updated to a newer height/hashExpected compiled-in block hashes digest changedNo new code paths, cryptographic changes, or bug fixes visible in the diff
b0a9d51eby tobtoht+7−74 files
No security note in commit
Low 38 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11448

This is a small code fix in Monero's wallet that keeps the recorded breakdown of received amounts consistent when a transaction output is 'burnt' (replaced or spent as part of a transaction the wallet is processing). The change adds a chec…

Defensive consistency check added (THROW_WALLET_EXCEPTION_IF)Fixes internal accounting of received output amountsNo explicit security claim in commit or supplied references
24a01223by tobtoht+7−01 file
No security note in commit
Moderate 60 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11443

This patch fixes a spot in the Monero wallet where an untrusted remote server (daemon) could supply a misleading 'status' field. Previously, the wallet used that raw status directly in its error handling, which could potentially make a mal…

Untrusted input from remote daemon used in error-handling pathMissing trust check on daemon-reported RPC statusSingle-call-site hardening patch
c03c1f15by tobtoht+1−11 file
No security note in commit
Informational 15 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11406

This commit adds two new read-only options to the wallet's remote procedure call (RPC) interface so users can request their public view key and public spend key. Public keys are meant to be shared openly and are not secrets, so exposing th…

717a4235by tobtoht+17−03 files
No security note in commit
Informational 15 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11394

This commit only updates a submodule pointer for the external polyseed library from one commit hash to another. The actual code changes inside the submodule are not shown in the diff, and no public references were supplied. There is no vis…

c437e73fby tobtoht+1−11 file
No security note in commit
Moderate 64 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11391

This patch fixes a size-limit accounting bug in Monero's built-in HTTP server. When a client sends multiple HTTP requests back-to-back on the same connection (pipelining), leftover buffered data from the next request was not being counted …

Request size limit bypass via pipelined HTTP cachingDenial-of-service / memory pressure potential from oversized requestsFix in low-level network protocol handler
9b24b744by tobtoht+2−11 file
No security note in commit
Moderate 51 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11386

This patch fixes a privacy leak in Monero's wallet RPC server. Previously, the --no-dns flag was ignored when no wallet was loaded, so the validate_address RPC call could still perform a DNS lookup (OpenAlias) even though the user had expl…

Privacy leak: RPC ignored --no-dns when no wallet loadedDNS lookup performed despite explicit user opt-outOpenAlias resolution could disclose queried addresses/aliases to DNS resolvers
9df95286by tobtoht+33−25 files
No security note in commit
Low 48 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11385

This commit adds cleanup of three additional memory buffers in Monero's seed-phrase key-stretching code. Before the change, leftover copies of intermediate secrets could remain in stack memory after the function finished. An attacker who c…

Sensitive intermediate key material left in stack memory after function returnUse of sodium_memzero to clear cryptographic buffersPBKDF2 implementation handling mnemonic-derived secrets
1cd8ae93by tobtoht+3−01 file
No security note in commit
Informational 21 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11383

This update improves the Monero wallet's command that connects to a network node (daemon). It lets users supply a username/password and a proxy address when switching daemons, and it replaces an older one-step connection method with a newe…

Added mutex lock in wallet2::set_proxy to protect concurrent access to proxy and HTTP client stateset_daemon now passes RPC login credentials and proxy settings through the proper wallet2::set_daemon APITrust heuristic changed to only auto-trust local daemons when no proxy is in use
07e23b8fby tobtoht+78−172 files
No security note in commit
Low 42 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11253

This change alters how Monero creates a view-only wallet copy. Previously, the code exported outputs using a method that could strip some metadata. Now it copies the full internal transfer records directly, then wipes and clears the multi-…

Sensitive field sanitization before export (memwipe + clear of m_multisig_k)Change in data export path for view-only wallet creationPreservation of 'complete output metadata' implying previous path was incomplete
ff738959by tobtoht+9−31 file
No security note in commit
Moderate 69 AI analysisMessage 66 · Adequate
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11333

This Monero update hardens how public keys and transaction pubkeys are handled. It moves a low-level 'torsion clearing' routine into the core crypto library, adds checks that wallet/destination addresses are valid points on the main subgro…

Adds main-subgroup membership validation for public address keys (spend/view)Normalizes transaction public keys before use in payment-ID decryption and tx proofsMoves torsion-clearing primitive into core crypto layer to ensure consistent behavior
6f4b99abby tobtoht+178−15016 files
No security note in commit
Moderate 63 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11268

This Monero update fixes a networking bug where the server could accidentally block all of its worker threads while waiting for slow clients to accept data. If all workers became stuck this way, the node could stop processing any network t…

Removal of blocking condition-variable wait in network send pathFail-fast on send-queue overflow instead of parking worker threadsHTTP handler now propagates send failures and enters error state
dba16f07by tobtoht+205−3025 files
No security note in commit
Moderate 59 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11260

This Monero wallet patch adds stronger safety checks when a wallet prepares, signs, or loads multi-step transactions (unsigned transactions, multisig transactions, and cold-device transactions). It verifies that money going into the transa…

Adds duplicate-input detection across transaction setsAdds destination address type consistency checksAdds uint64 overflow guard for summed input amounts
66dd773eby tobtoht+265−454 files
No security note in commit
Low 34 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11144

This Monero update makes the network layer clean up leftover block download records when a peer connection fails or is rejected. Previously, rejected or disconnected peers could leave stale block spans in a queue, which might cause the nod…

Denial-of-service resistance: stale block spans from malicious or faulty peers could prevent a node from obtaining valid blocksState cleanup on peer disconnection/rejectionNo authentication or memory-safety bug evident in diff
ddfa2279by tobtoht+2−01 file
No security note in commit
Low 46 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11362

This small patch fixes a bug in the Monero wallet where, if an output had already been scanned once, the wallet would return early without clearing an error flag. In rare cases this could leave a stale 'error' state attached to a transacti…

Stale error-state propagation in wallet scanning logicMissing reset of tx_scan_info.error on cached/short-circuit code pathPotential for incorrect received-payment or scan-failure reporting
30860a26by tobtoht+3−01 file
No security note in commit
Low 34 AI analysisMessage 58 · Thin
XMR Monero ProjectMonero Cryptographic librariesMoneroNode implementationsPrivacy protocols

Merge pull request #11366

This change fixes a binary search in the Monero wallet that previously could loop forever or behave incorrectly if something went wrong. The old code used an unbounded 'while (true)' loop and a midpoint calculation that could overflow. The…

Unbounded loop replaced with bounded iterationInteger overflow mitigation in midpoint calculationDefensive error handling added for search failure
c16cd3f7by tobtoht+4−21 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateblockchain: improve incoming block scan table handlingby selsta · 265e95a8 · Jun 29, 2026 · 1 fileMessage 50 · ThinLow 34Details
Commit message · selsta

blockchain: improve incoming block scan table handling

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Low 34/100

This commit refactors how Monero's blockchain code builds a lookup table used when checking incoming blocks. It replaces a slower, manual scan through offsets with a sorted binary search, and removes duplicate amount handling. The change appears to be a performance and correctness cleanup rather than a clear security fix, but the old code's linear search and duplicate-amount logic could theoretically hide or mishandle edge cases in block validation.

Security candidateOptimized handle_notify_new_transactions's duplicate tx check - Check sha256 digests instead of full blobs (much less memory used) - Replace `find->insert` sequence with a single `insert` - 2x fewer hashset accesses - Preallocate the required size for the hashset (no full-table rehashes)by SChernykh · 330062a0 · Jun 29, 2026 · 1 fileMessage 73 · AdequateInformational 19Details
Commit message · SChernykh

Optimized handle_notify_new_transactions's duplicate tx check
- Check sha256 digests instead of full blobs (much less memory used)
- Replace `find->insert` sequence with a single `insert` - 2x fewer hashset accesses
- Preallocate the required size for the hashset (no full-table rehashes)

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
cryptography-sensitive pathparser or protocol path
AI analysis · Informational 19/100

This commit is a performance optimization in Monero's transaction-processing code. It changes how the node detects duplicate transactions sent by a peer: instead of comparing the entire transaction data (which uses lots of memory), it compares small SHA-256 fingerprints. It also streamlines how those fingerprints are stored. There is no direct evidence this fixes a security bug, but it removes a memory-pressure path and hardens duplicate detection against subtle blob differences.

AI review queuedwallet2: avoid linear scans in pool state updatesby selsta · d40944c4 · Jun 28, 2026 · 2 filesMessage 45 · ThinInformational 19Details
Commit message · selsta

wallet2: avoid linear scans in pool state updates

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 19/100

This commit is a performance optimization in the Monero wallet. It replaces repeated linear list scans with hash-set lookups when checking which transactions are in the memory pool. The change should make wallet refresh faster when there are many pending transactions, but it does not appear to fix a security vulnerability or change behavior in a way that is directly exploitable.

Security candidateFix spelling typos in comments and string literalsby Thomas · fecef767 · Jun 27, 2026 · 32 filesMessage 50 · ThinInformational 15Details
Commit message · Thomas

Fix spelling typos in comments and string literals

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet pathparser or protocol path
AI analysis · Informational 15/100

This commit only fixes spelling mistakes in comments, documentation, and user-facing error/log strings. No program logic, calculations, or security behavior was changed. It is not a security fix and cannot be exploited.

AI review queuedwallet2: remove unused pool tx removed callbackby selsta · b1f45614 · Jun 26, 2026 · 2 filesMessage 68 · AdequateInformational 16Details
Commit message · selsta

wallet2: remove unused pool tx removed callback

on_pool_tx_removed has no implementation beyond the empty default callback
and is not wired through the wallet API layer.

The only call site passed txid after erasing the payment entry that owned it,
leaving a dangling reference.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 16/100

This commit removes a leftover wallet callback function that did nothing useful. The callback was called after a transaction record had already been deleted, so the transaction ID it received was technically invalid (a 'dangling reference'). Because the callback had no real implementation and was not exposed through the public wallet API, this appears to be a cleanup of dead code rather than a fix for an actively exploitable bug. The main risk is avoiding undefined behavior if someone later tried to use that invalid reference.

Security candidatetests: add CLSAG fuzz testsby selsta · 01e06da4 · Jun 25, 2026 · 15 filesMessage 70 · AdequateInformational 15Details
Commit message · selsta

tests: add CLSAG fuzz tests

Co-authored-by: Nym Seddon <unseddd@shh.xyz>

70/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification
Why it was queued
fuzzing or regression evidenceprivacy or spend-authorization protocol
AI analysis · Informational 15/100

This commit only adds new software tests (fuzz tests) for Monero's CLSAG ring signature verification code. It does not change any production code that handles transactions, wallets, or network data. Fuzz tests feed random or crafted data to a function to check it behaves safely, but the tests themselves are not a vulnerability or a fix. There is no indication this commit addresses a known security bug.

Security candidatetests/fuzz: fix cold-outputs importby jeffro256 · 70bdd2d9 · Jun 25, 2026 · 4 filesMessage 55 · ThinInformational 16Details
Commit message · jeffro256

tests/fuzz: fix cold-outputs import

55/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Mentions testing or verification! No meaningful explanatory body
Why it was queued
fuzzing or regression evidenceauthentication path
AI analysis · Informational 16/100

This commit updates a Monero fuzz test that feeds random or crafted data to the wallet's cold-output import code. It only changes test files and test code; no production wallet or node code is modified. The change makes the fuzzer use the newer, safer import path (import_outputs_from_str) and adds a testnet wallet setup. On its own, this is a test-harness cleanup, not a fix for a live security bug.

Security candidatep2p: restore safe sync mode when target height dropsby selsta · d8f3b81f · Jun 24, 2026 · 1 fileMessage 50 · ThinLow 46Details
Commit message · selsta

p2p: restore safe sync mode when target height drops

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathparser or protocol path
AI analysis · Low 46/100

This small patch changes Monero's peer-to-peer sync logic so that when the node's estimated target blockchain height suddenly drops, it re-enables 'safe sync mode' if the target is now very close to the node's current height. Safe sync mode is a more conservative way of downloading and verifying blocks. The change is defensive: without it, a node might stay in a faster but less safe sync mode even when the network no longer appears to be far ahead, which could make it more vulnerable to a malicious peer manipulating its view of the chain height. The commit message does not call this a security fix, and no independent researcher is credited.

AI review queuedwallet: store fee for not_enough_{unlocked_,}balanceby tobtoht · 06221f20 · Jun 24, 2026 · 1 fileMessage 50 · ThinInformational 15Details
Commit message · tobtoht

wallet: store fee for not_enough_{unlocked_,}balance

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds a 'fee' field to two existing wallet error types (not_enough_unlocked_money and not_enough_money). It does not change how transactions are validated, how fees are calculated, or how money is handled. It simply lets the wallet remember and report what fee was involved when an error about insufficient balance occurs. There is no security issue visible in this change.

AI review queuedtests: remove dead transactions_generation_from_blockchainby Thomas · 8a744a63 · Jun 23, 2026 · 3 filesMessage 73 · AdequateInformational 15Details
Commit message · Thomas

tests: remove dead transactions_generation_from_blockchain

Functional test commented out since 2014 (296ae46ed); never #included or
called (main.cpp only runs transactions_flow_test).

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Provides detailed explanatory context✓ Mentions testing or verification
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit simply deletes an old, unused test file and its header. The code being removed was entirely commented out since 2014, was never compiled into the test program, and was never run. It has no effect on the live Monero software or its users.

Security candidatecommon: remove unused data_cache.hby Thomas · b5136b1a · Jun 23, 2026 · 2 filesMessage 60 · AdequateInformational 15Details
Commit message · Thomas

common: remove unused data_cache.h

Dead since 40eb82873 (2025-10) moved verRct caching into the mempool;
only a stale #include remained in blockchain.cpp.

60/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit simply deletes an unused header file and removes its leftover include statement. It is a cleanup change with no functional or security effect on the running software.

AI review queuedhttp: parse server Content-Length strictlyby alhudz · 07f7c752 · Jun 23, 2026 · 2 filesMessage 45 · ThinModerate 51Details
Commit message · alhudz

http: parse server Content-Length strictly

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Moderate 51/100

This commit tightens how Monero's built-in HTTP server reads the 'Content-Length' header. Previously, the server would accept malformed values like '5abc' or '0x10' and silently use only the leading digits as the body length. Now it rejects the whole value unless it is a plain number. This kind of lenient parsing can cause request smuggling or desynchronization between the server and other HTTP components, which attackers can sometimes exploit to bypass security controls or poison caches.

AI review queuedsimplewallet: fix some more typosby jpk68 · 14e17537 · Jun 22, 2026 · 1 fileMessage 45 · ThinInformational 15Details
Commit message · jpk68

simplewallet: fix some more typos

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit fixes three spelling mistakes in user-facing error messages inside Monero's command-line wallet. There are no code logic changes, no security fixes, and no functional impact.

Security candidatecmake: set message mode everywhereby tobtoht · 9ed0a114 · Jun 21, 2026 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · tobtoht

cmake: set message mode everywhere

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
cryptography-sensitive pathsigning or wallet pathdocumentation-only discount
AI analysis · Informational 15/100

This commit only changes two CMake build messages from plain 'message(...)' to 'message(STATUS ...)'. That is a cosmetic/logging change: it tells CMake to print these lines as informational status messages instead of bare output. It does not change any compiled code, cryptographic logic, wallet behavior, or security boundary.

AI review queuedhttp: share deterministic header field parserby selsta · 389f3660 · Jun 21, 2026 · 4 filesMessage 45 · ThinModerate 66Details
Commit message · selsta

http: share deterministic header field parser

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Moderate 66/100

This commit replaces a complex regular-expression-based HTTP header parser with a single, stricter, hand-written parser shared between the client and server code. The old parser could silently accept malformed or ambiguous headers, which in HTTP can lead to security problems such as request smuggling, cache poisoning, or unexpected behavior. The new parser rejects headers that do not follow a well-defined format and validates the characters allowed in header names. It also adds many tests that demonstrate malformed headers are now rejected. The commit itself does not describe this as a security fix, but the change clearly reduces attack surface in the way Monero's HTTP stack processes incoming and outgoing headers.

AI review queuedwallet: add missing copyright infoby jpk68 · 473035ea · Jun 21, 2026 · 3 filesMessage 45 · ThinInformational 15Details
Commit message · jpk68

wallet: add missing copyright info

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit only adds standard copyright and license notice blocks to the top of three wallet source files. It does not change any program logic, data handling, or user-facing behavior, so it has no security impact on the Monero software itself.

Security candidatecryptonote_basic: copy tx extra payment IDsby Ap4sh · f4047aeb · Jun 21, 2026 · 2 filesMessage 45 · ThinLow 29Details
Commit message · Ap4sh

cryptonote_basic: copy tx extra payment IDs

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
privacy or spend-authorization protocolcryptography-sensitive path
AI analysis · Low 29/100

This commit changes how Monero reads payment IDs embedded in transaction data. Previously, the code used a type-casting pointer trick to read the bytes; now it uses memcpy, which is the safer, standard way to copy raw bytes. The change is defensive and reduces the risk of subtle memory alignment or aliasing problems, but the commit itself does not claim to fix an active security bug.

AI review queuedwallet2: avoid std::out_of_range on a truncated tx set blobby Thomas · 36bb2d0e · Jun 20, 2026 · 1 fileMessage 73 · AdequateLow 28Details
Commit message · Thomas

wallet2: avoid std::out_of_range on a truncated tx set blob

parse_unsigned_tx_from_str() and parse_tx_from_str() strip the magic,
then read the version byte and call s.substr(1) without checking a
version byte follows. A blob equal to just the magic leaves an empty
remainder, so s.substr(1) throws std::out_of_range instead of the
function returning false. Require magic + a version byte first.

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 28/100

This commit fixes a minor crash bug in Monero's wallet code. When the wallet tried to read a transaction data blob that contained only the file-type 'magic' header and nothing else, it would throw an uncaught out-of-range exception instead of cleanly reporting 'bad data.' The patch makes the wallet check that at least one byte follows the magic before reading it, turning the crash into a normal error return.

Security candidateFix spelling typosby Thomas · 02db831d · Jun 18, 2026 · 35 filesMessage 28 · OpaqueInformational 15Details
Commit message · Thomas

Fix spelling typos

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive pathsigning or wallet pathparser or protocol path
AI analysis · Informational 15/100

This commit is a routine cleanup that fixes spelling mistakes and typos across comments, error messages, variable names, and documentation strings. None of the changes alter program logic, data handling, or security behavior. The only file rename (instanciations.cpp → instantiations.cpp) is a spelling correction, and the CMakeLists.txt reference is updated to match. There is no security impact.

AI review queueddepends: Bitcoin -> Monero typoby jeffro256 · a6c9d62e · Jun 17, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · jeffro256

depends: Bitcoin -> Monero typo

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI analysis · Informational 15/100

This commit fixes a single-word typo in a documentation file, changing 'Bitcoin' to 'Monero' in a sentence describing the dependency build system. It has no effect on program code, behavior, or security.

Security candidatecryptonote_basic: remove unused functionby jpk68 · d7e23999 · Jun 17, 2026 · 1 fileMessage 35 · OpaqueInformational 15Details
Commit message · jpk68

cryptonote_basic: remove unused function

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
cryptography-sensitive path
AI analysis · Informational 15/100

This commit simply deletes a helper function called power_integral that was not being used anywhere in the code. It is a routine cleanup with no visible security effect.

AI review queuedwallet2: read multisig restore fields with memcpy in generateby alhudz · 6ad3dc08 · Jun 15, 2026 · 1 fileMessage 50 · ThinLow 48Details
Commit message · alhudz

wallet2: read multisig restore fields with memcpy in generate

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 48/100

This commit changes how a Monero wallet reads sensitive key data from a multisig restore string. Previously, the code directly cast a pointer to the data buffer and read keys as if they were already in the correct structure. Now it uses memcpy, which is the safer, standard way to copy raw bytes into typed variables. The main practical concern is avoiding undefined behavior from unaligned or improperly typed memory access, especially for secret key types that may have stricter alignment requirements. It is a hardening fix rather than a clear-cut remote exploit.

AI review queuedwallet2: reject non-monotonic rct output distributionsby selsta · 7578af44 · Jun 15, 2026 · 1 fileMessage 50 · ThinModerate 61Details
Commit message · selsta

wallet2: reject non-monotonic rct output distributions

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Moderate 61/100

This change makes the Monero wallet refuse to build transactions if the list of RingCT output counts it gets from a daemon is not in ascending order. A non-monotonic (out-of-order or decreasing) distribution could indicate a misbehaving or malicious daemon trying to trick the wallet into selecting invalid or non-existent outputs, which might lead to failed transactions or privacy/funds issues. The patch is a defensive check, but it is small and does not by itself prove an active attack is possible.

AI review queuedwallet: wallet args take argv[] as constby jeffro256 · e9a8a268 · Jun 15, 2026 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · jeffro256

wallet: wallet args take argv[] as const

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit changes the wallet's command-line argument handling so the program's input arguments are treated as read-only (const). It is a code-quality and type-safety improvement, not a security fix. There is no indication it prevents or fixes any exploit.

AI review queuedsimplewallet: misc safety/correctness fixesby jpk68 · 6aba4596 · Jun 12, 2026 · 1 fileMessage 45 · ThinLow 34Details
Commit message · jpk68

simplewallet: misc safety/correctness fixes

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 34/100

This commit fixes several crash bugs and one possible underflow bug in Monero's command-line wallet (simplewallet). Most changes add null-pointer checks before using the wallet object, preventing the program from crashing if a user runs commands before a wallet is loaded. One change prevents a subtraction from going below zero when computing the number of 'fake' transaction outputs. Another change removes an incorrect argument-count check in the device-name command. The commit is described by its author as general safety/correctness fixes, not as a security patch.