MJ
← Watched projectsVendor accountability

monero-java

Vendor website ↗
Security hygiene0/100 · Insufficient dataPreliminary score
How the vendor scores

Security hygiene breakdown

Disclosure quality 0/100
Researcher acknowledgement 0/100
Security process 0/100
Patch clarity 0/100
Response quality 0/100
Accountability record

Recent watches

Informational 24 AI analysisMessage 50 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: send amounts to wallet rpc as json numbers for v0.18.5.3

This commit changes how the Java wallet library sends monetary amounts to the Monero wallet RPC server. Previously, amounts were converted to strings before being sent; now they are sent as JSON numbers. This is a compatibility fix for Mon…

Data type mismatch between client and RPC server could lead to failed or misinterpreted transactionsAmount handling changes in transaction creation and reserve proof generation pathsNo input validation or bounds checks added in the patch
6d0cd696by woodser+3−31 file
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

docs: update api docs

This commit only updates generated Java API documentation (Javadoc HTML files). It adds descriptions explaining how SSL/TLS certificate verification works when connecting to a Monero daemon. No actual program code was changed, so this comm…

f93bae8eby woodser+17−45 files
No security note in commit
Informational 15 AI analysisMessage 67 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

ci: run TLS regression tests

This commit only changes the project's automated build configuration to run a few extra tests during continuous integration. It does not modify any application code, libraries, or user-facing behavior. There is no security fix or vulnerabi…

8c6f97c0by woodser+3−31 file
No security note in commit
Moderate 59 AI analysisMessage 60 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: propagate TLS verification to native and RPC wallets

This commit fixes how Java wallet code passes TLS/SSL certificate verification settings down to the underlying native Monero wallet and to RPC wallets. Previously, the Java layer could request 'verify the certificate' or 'allow any certifi…

TLS/SSL verification preference now propagated across JNI to native walletRPC wallet now translates connection sslVerify into ssl_allow_any_cert and ssl_support parametersConnection equality/hashCode now includes sslVerify, preventing silent mismatches
43c2a9ecby woodser+240−4010 files
No security note in commit
Informational 15 AI analysisMessage 40 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

docs: update api docs

This commit only updates generated API documentation (Javadoc HTML files). It does not change any actual program code, so it cannot introduce or fix a security vulnerability on its own.

bf0ac8c3by woodser+278−2317 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: isolate key image import test

This commit only changes a test file. It rewrites one wallet test so that it uses a separate offline wallet instead of importing outputs back into the same wallet. There is no change to production code and no security fix or vulnerability …

86567073by woodser+16−151 file
No security note in commit
Informational 15 AI analysisMessage 75 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: sync balances before multi-destination sends

This commit only changes a test file. It makes a wallet test wait for mining to stop and sync balances before checking send results. There is no change to production wallet code, no user-facing behavior change, and no security fix.

e6fd994cby woodser+4−01 file
No security note in commit
Informational 23 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: retain unlock notifications after long polling gaps

This change fixes a bug in a Monero wallet's long-polling notification system. Previously, if there was a long gap between polls, the wallet could use a height bound that was too recent and miss transactions that had since unlocked. The fi…

Functional bug in wallet notification logicPotential missed unlock notifications after polling gapsNo cryptographic, authentication, or input-validation changes
7a1a3af4by woodser+6−21 file
No security note in commit
Informational 14 AI analysisMessage 75 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: synchronize notification balances before sending

This commit only changes a test file. It makes the wallet notification tests more reliable by syncing balances before sending and ensuring mining, listeners, and temporary wallets are cleaned up even if the test fails. There is no change t…

555c973bby woodser+237−2071 file
No security note in commit
Low 35 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: reset snapshots when switching wallets

This commit fixes a lifecycle bug in the Monero Java wallet library. When a user switches from one wallet to another, background polling and notification threads could keep running with stale data from the previous wallet. The patch adds g…

stale callback invalidation across wallet lifecycle changesgeneration-counter pattern to prevent use of stale snapshotsbackground poller and ZMQ listener reset on wallet clear/switch
2bdc3fc8by woodser+105−322 files
No security note in commit
Low 26 AI analysisMessage 65 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: restore callbacks when reopening wallets

This commit fixes a state-tracking bug in a Monero wallet library. When a wallet client object was reused to open or create another wallet, an internal 'closed' flag was not reset. This could leave event/callback listeners disabled on the …

State-management bug in wallet lifecycleMissing reset of closed flag on reused RPC clientPotential loss of transaction/sync callbacks after wallet reopen
e6a5b8d5by woodser+2−01 file
No security note in commit
Informational 15 AI analysisMessage 83 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: wait for wallet pending state before equality

This commit only changes test code. It makes wallet equality tests wait for pending transactions to fully clear from the wallets' own state before comparing balances and rescanning spent outputs. There is no change to production wallet log…

eb72c61cby woodser+5−52 files
No security note in commit
Informational 14 AI analysisMessage 60 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

tests: mine to height before checking sync notifications

This commit only changes test code. It refactors how a Monero wallet test waits for a new block by introducing a helper that mines until a specific blockchain height is reached, instead of starting mining and waiting for the next block in …

4f38f454by woodser+33−272 files
No security note in commit
Low 43 AI analysisMessage 68 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet full: cancel native calls before closing

This commit hardens how the Java Monero wallet shuts down. It makes sure background native (C++) calls are cancelled and finish before the wallet is freed, and it protects listener cleanup from running at the same time as notifications. Th…

Use-after-free / double-free risk in close pathRace condition between native listener callbacks and wallet destructionCross-thread JNIEnv handling in JNI listener destructor
e949b9e1by woodser+123−576 files
No security note in commit
Informational 22 AI analysisMessage 73 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: announce missed confirm transition when tx unlocks between polls

This commit fixes a notification bug in a Monero wallet library. Previously, if a transaction both confirmed and became unlocked between two polling checks (which can happen during fast block times), the wallet would only announce the 'unl…

No security-relevant signals present in commit message or diffChange is a state-transition notification ordering fixNo input validation, cryptographic, authorization, or memory-safety changes
37bfe4a5by woodser+6−01 file
No security note in commit
Informational 17 AI analysisMessage 95 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test: update offline wallet expectations for ungated daemon calls

This commit only changes test code. It updates the expected behavior of an offline Monero wallet so that certain daemon-related calls no longer throw a 'not connected' error. The underlying wallet behavior was already changed elsewhere; th…

Test-only changeError message masking from untrusted daemons mentioned in commentBehavior alignment with monero-wallet-rpc auto_refresh
5eb65343by woodser+4−51 file
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test correct restore heights after closing wallet

This commit only updates test expectations in a Java test file. It changes three comments/assertions so that the test now expects a wallet's restore height to be remembered after closing, rather than expecting it to be lost. There is no pr…

246ab28dby woodser+3−31 file
No security note in commit
Moderate 59 AI analysisMessage 73 · Adequate
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet: prevent close from freeing wallet during in-flight calls

This commit fixes a race condition in a Monero wallet Java library. Previously, calling close() on a wallet could free the underlying native wallet memory while other operations were still running, which could cause crashes or unpredictabl…

Race condition between wallet close() and in-flight native callsPotential use-after-free of C++ wallet handle (jniWalletHandle)New read/write locking around all JNI wallet operations
5c01e76cby woodser+883−4682 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 95 · Strong
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

test: update sync progress tests for throttled progress with hash-skip reporting

This commit only updates test code to match a new wallet behavior where sync progress notifications are throttled and may report a temporary 'hash-skip' phase. There are no product code changes, no bug fixes, and no security-relevant behav…

9872555aby woodser+20−151 file
No security note in commit
Informational 23 AI analysisMessage 50 · Thin
MJ monero-javamonero-java Cryptographic librariesMoneroSoftware wallets

wallet rpc: bound getTxs re-fetch on inconsistency

This change fixes a potential infinite recursion bug in the Monero wallet RPC client. Previously, when the software detected inconsistent transaction data from multiple RPC calls, it would repeatedly re-fetch the data forever. Now it limit…

Unbounded recursion / retry loop replaced with bounded retry limitPotential denial of service via stack overflow or unresponsive wallet RPC clientError handling added for unresolvable data inconsistency
8c7dcc35by woodser+7−21 file
No security note in commit