AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 35 Cryptographic libraries

daemon: remove miniupnp

Public commit record

What the developer wrote

Authored by tobtoht

28/100 · Opaque
daemon: remove miniupnp
✓ Subject identifies a change! No meaningful explanatory body
The short version

What changed, and why it matters

This commit removes the miniupnp library and all UPnP port-forwarding support from the Monero daemon. UPnP is a protocol that lets programs automatically open ports on home routers, but it has a long history of security bugs and can expose services to the internet unexpectedly. The change keeps the --igd command-line option for backward compatibility but makes it non-functional, and removes the --no-igd option because it is no longer needed. This is a defensive hardening change rather than a fix for a specific known Monero vulnerability.

Recommended action

Treat this as a hardening improvement. Users who previously relied on UPnP automatic port mapping will now need to forward ports manually. Review the unrelated tests/fuzz/CMakeLists.txt if(OSSFUZZ) change separately to ensure intended fuzz targets are still built when needed. No urgent patch action is required.

Security signals we found

01

Removal of third-party dependency with known security history (miniupnpc)

02

Disabling of UPnP/IGD port mapping feature that could expose listening ports

03

Backward-compatibility warning added for deprecated --igd option

04

No replacement UPnP implementation introduced

Risk score

Why this scored 35/100

Our methodology →
Potential impact 8/30
Exploitability 5/25
Stealth signal 4/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.