Live Prices
Bitcoin

Core Lightning Releases v26.06.9 to Fix Critical Security Vulnerabilities and Bitcoin Payment Bug

TheCryptoDesk Editorial · 2m read
Core Lightning Releases v26.06.9 to Fix Critical Security Vulnerabilities and Bitcoin Payment Bug

Core Lightning, a major software implementation for running Bitcoin Lightning Network payment nodes, has released version v26.06.9 to patch critical security vulnerabilities and resolve a performance regression that delayed payment traffic on busy nodes. Published on GitHub on Oct. 7 with a changelog dated Oct. 6, the update follows a Sept. 27 patch in v26.06.7 that resolved a revoked-channel penalty flaw.

Performance Regression and HTLC Shutdown Fixes

The previous release, v26.06.8, introduced a regression where routine ping messages, onion messages, and gossip were improperly counted against a CPU budget allocated specifically for gossip queries. On high-traffic nodes, this accounting error throttled peers and delayed channel payment processing. Version v26.06.9 reserves that budget solely for gossip queries, eliminating the documented traffic bottleneck.

Additionally, maintainers addressed a contract vulnerability involving Hash Time-Locked Contracts (HTLCs). If an HTLC reaches its deadline while a channel is shutting down, v26.06.9 will now automatically force-close the channel. This prevents forwarded funds from being lost if the payment is fulfilled late during channel closure.

Security Hardening and Admin Safeguards

Beyond network traffic fixes, the update introduces key security safeguards for node operators:

  • Rune Authorization Limits: Enforces restrictions on administrative runes, preventing restricted runes from generating unrestricted ones or relisting blacklisted items via aliases like invokerune and destroyrune.
  • Sensitive Data Masking: Updates the listconfigs command to redact sensitive values, including recovery information and Bitcoin RPC passwords, for all callers.
  • Config Injection Patch: Patches setconfig to close a vulnerability that allowed configuration line injections through persistent option values.
  • Test Holdback: Security test suites have been temporarily withheld by maintainers to delay exploit development while operators upgrade node infrastructure.

Maintainers urge node operators to upgrade immediately, echoing the broader technical maintenance required across Layer-1 infrastructure, such as recent Bitcoin Core protocol updates. The release notes also warn that nodes running the master branch cannot downgrade to the 26.06.x series due to database schema changes, while reiterating that dual funding remains experimental and zero-confirmation channels with untrusted peers are discouraged.

Why It Matters

This rapid patch cycle highlights the technical complexity of maintaining Layer-2 infrastructure on Bitcoin. For routing nodes processing high transaction volumes, CPU accounting errors and HTLC edge cases present direct financial and operational risks. By quickly resolving privilege escalation paths and config credential leaks, maintainers are actively hardening node security as commercial usage of the Lightning Network grows.

Terms in this article

Read next