Core Lightning tells node operators to shut down immediately, patch not yet available

2 days ago 1



Core Lightning, the Lightning Network implementation maintained by Blockstream, issued an urgent advisory on August 26 telling node operators to take their nodes offline immediately. The catch: the patched version hasn’t been released yet, meaning operators can’t upgrade even if they want to. Their only option right now is pulling the plug. Any node running CLN version 26.04 or earlier is affected, and those versions will no longer receive support. The maintainers say signed binaries for a fixed release are being prepared, but the specific vulnerabilities will remain under a two-week embargo. What triggered the advisory The disclosure came after CLN developers received a flood of AI-generated CVE reports over a ten-day period. CVEs, or Common Vulnerabilities and Exposures, are the standardized way security researchers flag software flaws. Receiving a burst of them, especially ones generated by AI tools rather than human researchers, apparently surfaced real exploitable issues in the process. The team hasn’t published technical details, which is standard practice for critical vulnerabilities where immediate exploitation is possible. The two-week embargo gives operators time to patch...

Read Entire Article