Security· ★★★· neutral·

Core Lightning patches critical security flaws and a Bitcoin payment bug

  • —v26.06.9 fixes a v26.06.8 regression where routine messages consumed the CPU budget reserved for gossip queries
  • —HTLCs expiring during channel shutdown now trigger a force-close, protecting forwarded funds
  • —Rune limits are enforced: a restricted rune can no longer create an unrestricted one or relist blacklisted runes
  • —listconfigs now masks Bitcoin RPC passwords and recovery data; setconfig blocks config injection
Why it matters: Node operators should upgrade promptly, as the flaws affect security and the safety of forwarded Lightning payments.
Source: CryptoSlate