
OtherCVSS 10€0
Critical Deadlock Vulnerability in Monero RPC Leading to Complete Node Paralysis
rorkh
Disclosed on HackerOne · May 6, 2026
Publicly disclosed report · by rorkh
View original on HackerOneSummary:
A deadlock vulnerability in Monero's JSON-RPC interface allows a remote, unauthenticated attacker to completely paralyze any Monero node with a single HTTP request containing specific batch methods, leading to permanent denial of service.
Releases Affected:
- Monero 'Fluorine Fermi' (v0.18.4.2-2987b7200)
- Likely all previous versions
- All operating systems (Linux, Windows, macOS)
- All run modes (mainnet, testnet, offline, restricted-rpc)
Severity: