Monero 0.18.5.3 hardens restricted RPC nodes and wallets against malicious remote nodes
The Monero project released version 0.18.5.3, "Fluorine Fermi", on 6 October and calls it a highly recommended release with a large number of bug fixes. It is the work of 17 people, 182 commits and 4,162 new lines of code, according to the announcement.
For node operators.
- Public IPv6 connection limits are now grouped by /64, so one network block counts as one source.
- Restricted RPC, the mode used by public nodes, gets several privacy changes:
get_transaction_poolis disabled, privacy filtering is improved,get_public_nodesreturns only public-zone peers, deep block submissions are rejected, and ZMQ hides request contents from logs. - Rejected block spans from disconnected peers are flushed; handshake and timeout handling, LMDB resizing, and transaction serialization and validation are improved.

For wallets.
- Hardening against malicious remote nodes, in four separate changes.
- Better transaction validation for cold and multisig signing; all copies of multisig nonces are now erased together; fixes for multisig output import and refresh.
- Key image domains are validated in reserve proofs, and an infinite loop when estimating transactions with many outputs is fixed.
- The wallet RPC adds transaction weight to
describe_transfer.
Also: protection against log injection from malformed JSON and HTTP headers, a size check on Trezor bridge responses, and fixed HTTP connection reuse after remote disconnects.
Binaries are on the project's downloads page with SHA256 hashes published in the announcement; the full change list is on GitHub. A GUI release with the same version number was announced the same day.
Primary source
getmonero.org
https://www.getmonero.org/2026/10/06/monero-0.18.5.3-released.htmlWritten by Victoria Shinder.