Core Lightning confirms multiple vulnerabilities, prepares security update

Summary

Core Lightning, a Bitcoin Lightning Network implementation, confirmed that several recently reported vulnerabilities are real and said a security update is coming. It advised node operators to upgrade as soon as possible. Until then, operators should not fully shut down nodes; instead, they can restart the daemon with `--offline`, which keeps the software running and tracking the Bitcoin blockchain while preventing it from sending, receiving, or routing payments. Core Lightning said this mode helps nodes respond if a counterparty force-closes a channel. It also warned operators to remove `--offline` after upgrading, or the node will stay disconnected. The project did not disclose the flaws’ details, severity, CVE IDs, or any exploitation. These issues are separate from earlier patched remote denial-of-service bugs disclosed in May and July.