HackerOne Disclosed Reports - 2026-07-24

0 Replies, 5 Views

Logo
Medium
resolved

ZMQ RPC Log Injection and Untrusted Payload Persistence


Bug reported by redlobsterz was disclosed at July 24, 2026, 7:19 pm   |   CRLF Injection

A vulnerability was reported in the Monero CLI daemon where the ZMQ RPC request path logs untrusted request content before semantic validation. This allowed a remote party with access to the ZMQ endpoint to inject newline and control-character content into daemon logs, enabling log forging. The vulnerability was introduced in commit 77986023c3 and affected releases from v0.12.0.0 through v0.18.4.6, as well as the master branch as of the reported date.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)