
Core Lightning patches critical security flaws and a Bitcoin payment bug
- —v26.06.9 fixes a v26.06.8 regression where routine messages consumed the CPU budget reserved for gossip queries
- —HTLCs expiring during channel shutdown now trigger a force-close, protecting forwarded funds
- —Rune limits are enforced: a restricted rune can no longer create an unrestricted one or relist blacklisted runes
- —listconfigs now masks Bitcoin RPC passwords and recovery data; setconfig blocks config injection
Why it matters: Node operators should upgrade promptly, as the flaws affect security and the safety of forwarded Lightning payments.
Source: CryptoSlate