Key points

  • Core Lightning says version 26.06.9 contains security fixes across channel, HTLC, onion, gossip, authorization and configuration components.
  • The release repairs a v26.06.8 CPU-budget regression that could delay ordinary channel traffic on busy nodes.
  • Maintainers recommend upgrading promptly but have temporarily withheld security tests to slow exploit development.

Core Lightning has released version 26.06.9, urging operators of Bitcoin Lightning payment nodes to upgrade after fixing security weaknesses and a performance regression introduced in the previous point release. The maintainers published the update on October 7 and refreshed its release information on October 9.

A repair for busy-node traffic delays

The clearest operational change concerns how Core Lightning budgets processor time for network messages. In version 26.06.8, routine gossip, pings and onion messages could count against a budget intended for gossip queries. On heavily used nodes, that accounting could throttle peers and delay channel traffic. Version 26.06.9 limits the budget to gossip queries, removing the documented cause of the slowdown.

Related reporting: Lightning bug could mark canceled Bitcoin invoices as paid

That distinction matters because Lightning payments depend on nodes relaying messages and payment contracts across a network of channels. A delay at a busy routing node can degrade payment reliability even when Bitcoin's base layer is functioning normally. Merchants, payment processors and routing operators may see the effect as slower forwarding or more fragile channel activity rather than an obvious software crash. The release does not claim that every failed or slow payment had this cause; it addresses a specific regression affecting nodes running 26.06.8.

Security fixes extend beyond performance

The maintainers also list fixes involving channel reestablishment, splicing, HTLC handling during shutdown, onion messages, on-chain processing, gossip range queries, authorization runes and runtime configuration. One change force-closes a channel when a forwarded hashed time-locked contract reaches its deadline during shutdown, preventing a late fulfillment from putting the forwarding node's funds at risk.

Authorization controls were tightened as well. A restricted rune can no longer create a new unrestricted rune or relist a blacklisted rune, and related aliases now receive equivalent checks. The listconfigs command masks wallet and recovery information, Tor service passwords, Bitcoin RPC passwords and an older bookkeeping database field for every caller. The setconfig path was also hardened against persistent option values that could inject configuration lines.

Some technical details remain private for now

Core Lightning made the fixes available immediately and did not impose an embargo. However, the project has temporarily withheld the tests for its security patches. Maintainers said the pause is intended to make it harder to turn the fixes into working exploits before operators have time to update. That means the release identifies affected areas but does not yet provide complete public reproduction steps for every vulnerability.

The release also adds reproducible ARM64 and ARMv7 binaries for supported Ubuntu versions, with separate signed checksum manifests. Operators are told to verify both signatures and file checksums. Nodes that have run development builds cannot downgrade to the 26.06.x line because their database schema is newer, while dual funding remains experimental and zero-confirmation channels with untrusted peers remain discouraged.

What operators should watch

For node operators, the immediate issue is software exposure rather than Bitcoin's market price. The maintainers strongly recommend moving to 26.06.9 as soon as practical, including for users already on 26.06.8. A staged upgrade, package verification and channel-state backups can reduce operational risk, especially for nodes that handle meaningful payment volume. Operators should follow the project's signed-release verification process, confirm their installed package and monitor subsequent disclosures when the withheld tests and fuller vulnerability details are published.

Sources

AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.