Core Lightning v26.06.9 Rolls Out Security Fixes, Resolves Busy-Node Payment Slowdowns

AI Market Summary
Core Lightning v26.06.9 patches multiple security and reliability issues, including a v26.06.8 regression that could throttle peers and delay Lightning channel traffic on busy nodes, plus an HTLC edge case that could risk forwarded funds during shutdown. The release also tightens rune permissions and masks sensitive configs, with security tests temporarily withheld to slow exploit development. Near-term focus is operational risk management for Lightning routing nodes.
Impact level
● Medium
Affected assets
BTC/USDT-0.14%
AI Insight · BTC/USDTAI Insight
● Neutral
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Core Lightning, the software used to run Bitcoin Lightning payment nodes, has shipped version 26.06.9 with security fixes and a repair for a regression that could slow channel traffic on heavily loaded nodes running v26.06.8. GitHub shows the release as published on Oct. 7, while the versioned changelog is dated Oct. 6. The update gives operators who installed v26.06.8 a new decision point on upgrading after a Sept. 27 revokedchannel penalty issue that was addressed in v26.06.7. The newest patch adds further fixes and also tackles a regression introduced by the subsequent release. Busy-node throttling and payment delays Maintainers said that in v26.06.8, routine gossip, pings, and onion messages were counted against a CPU budget intended for gossip queries. On busy nodes, that accounting could throttle peers and delay channel traffic. Version 26.06.9 reserves the budget for gossip queries only, so ordinary messages no longer consume it, removing the stated cause of the throttling. The changelog also details a fix for cases where a payment contract (HTLC) hits its deadline while a channel is shutting down. In that scenario, v26.06.9 will now force-close the channel, aiming to prevent forwarded funds from being lost if the payment is fulfilled late. For operators forwarding payments, the change addresses a funds-protection risk when payment deadlines overlap with channel shutdown. Additional safeguards Core Lightning v26.06.9 also introduces shutdown, permission, and configuration protections. Other changes tighten enforcement of limits attached to runes used to authorize calls, preventing a restricted rune from creating an unrestricted one or relisting blacklisted runes. The same restrictions now apply to the invokerune and destroyrune aliases for the related creation and blocklisting methods. The listconfigs command now masks several sensitive values for all callers, including recovery information and Bitcoin RPC passwords. The setconfig command closes a route for injecting configuration lines through persistent option values. Maintainers said fixes are available immediately, but security tests have been temporarily held back to make exploit development more difficult and to give operators more time to upgrade. Nodes that have run master cannot downgrade to a 26.06.x release because their database schema is newer. The release reiterates that dual funding remains experimental and advises against zero-confirmation channels with untrusted peers. Maintainers urged Core Lightning users, including those on v26.06.8, to upgrade to v26.06.9 as soon as practical. The post Core Lightning patches critical security flaws and a Bitcoin payment bug appeared first on CryptoSlate.