Core Lightning, the node software for routing payments across Bitcoin's Lightning Network, shipped v26.06.9 on October 7 with a string of security patches plus a fix for a payment-routing regression introduced two weeks earlier in v26.06.8. The release arrives on the heels of v26.06.7, which patched a revoked-channel penalty bug disclosed September 27 and forced the team into a brief emergency lockdown. Together, three version bumps in roughly two weeks make this the most concentrated patch run Core Lightning has shipped in recent memory.
Why it matters
The headline bug was a CPU-budget accounting error: v26.06.8 began counting routine gossip, pings, and onion messages against a budget that should have been reserved for gossip queries. On busy routing nodes, the misclassification could throttle peers and delay channel traffic. V26.06.9 retires that budget to gossip queries only, removing the documented cause of the throttling. Maintainers are also temporarily withholding security tests from the public repository to slow exploit development and buy operators more time to upgrade before the test suite becomes a how-to guide for attackers.
Market impact
The funds-protection fix is the more consequential line in the changelog: when an HTLC reaches its deadline while a channel is shutting down, v26.06.9 now force-closes the channel so a late-fulfilled payment cannot lose forwarded funds. Rune permissioning is tightened so a constrained rune can no longer mint an unrestricted one or relist blacklisted entries, and the invokerune and destroyrune aliases fall under the same restrictions. Sensitive values in listconfigs, including recovery information and Bitcoin RPC passwords, are now masked for every caller. setconfig closes a path for injecting configuration lines through persistent option values. Operators on master cannot downgrade to 26.06.x because the database schema is newer, dual funding remains experimental, and zero-conf channels with untrusted peers are still discouraged.
Frequently asked questions
-
What does Core Lightning v26.06.9 actually fix?
It patches a CPU-budget accounting regression in v26.06.8 where routine gossip, pings, and onion messages were charged against a gossip-query budget, plus an HTLC force-close bug that risked losing forwarded funds, rune permissioning, and several configuration safeguards.
-
Why are maintainers withholding the security tests?
Maintainers are temporarily holding back the security test suite from the public repository to slow exploit development and buy operators more time to upgrade before the tests become a reference for attackers.
-
Do operators need to upgrade from v26.06.8?
Yes. Maintainers urge operators on v26.06.8 and earlier to upgrade as soon as practical. Nodes running master cannot downgrade to a 26.06.x release because their database schema is newer.
-
How does the HTLC fix protect forwarded funds?
When an HTLC reaches its deadline while a channel is shutting down, v26.06.9 now force-closes the channel instead of risking the forwarded payment being fulfilled late and the funds lost.
-
What other safeguards are in v26.06.9?
listconfigs now masks sensitive values including recovery information and Bitcoin RPC passwords for every caller, setconfig closes a configuration-injection path through persistent option values, and rune restrictions now cover invokerune and destroyrune aliases.
CryptoSlate