Getmonero maintains the Monero cryptocurrency and associated software, a focused but widely used privacy-focused digital currency implementation. Vulnerabilities in the project recur through resource-management issues such as allocation without limits or throttling, deserialization of untrusted data, and uncontrolled search path elements, reflecting the parsing, peer-to-peer networking, and cryptographic demands of a decentralized system. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getmonero over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3972CRITICAL An exploitable code execution vulnerability exists in the Levin deserialization functionality of the Epee library, as used in Monero 'Lithium Luna' (v0.12.2.0-master-ffab6700) and | Sep 26, 2018 | 9.8 | 30 | NO | NO |
CVE-2020-26947HIGH monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via | Oct 10, 2020 | 7.8 | 25 | NO | NO |
CVE-2025-26819HIGH Monero through 0.18.3.4 before ec74ff4 does not have response limits on HTTP server connections. | Feb 15, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getmonero.
Media articles that mention a CVE ID that affects a product developed by Getmonero — matched by CVE ID, not by vendor name.