AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 51 Cryptographic libraries

Merge pull request #11386

Public commit record

What the developer wrote

Authored by tobtoht

58/100 · Thin
Merge pull request #11386

0e2b994 wallet-rpc: honor --no-dns without a wallet (Samy)

ACKs: jpk68, selsta
✓ Descriptive subject✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This patch fixes a privacy leak in Monero's wallet RPC server. Previously, the --no-dns flag was ignored when no wallet was loaded, so the validate_address RPC call could still perform a DNS lookup (OpenAlias) even though the user had explicitly disabled DNS. This could leak which address or alias a user was checking to DNS servers. The fix makes the RPC server honor --no-dns and --offline flags even without a wallet open.

Recommended action

Users running monero-wallet-rpc with --no-dns or --offline should upgrade to ensure DNS is not silently used for validate_address when no wallet is loaded. Review other RPC endpoints for similar wallet-state-dependent flag handling.

Security signals we found

01

Privacy leak: RPC ignored --no-dns when no wallet loaded

02

DNS lookup performed despite explicit user opt-out

03

OpenAlias resolution could disclose queried addresses/aliases to DNS resolvers

04

Fix adds command-line flag checks independent of wallet state

Risk score

Why this scored 51/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.