Core Lightning patches critical security flaws and a Bitcoin payment bug

Core Lightning patches critical security flaws and a Bitcoin payment bug

Summary

Core Lightning released v26.06.9 with security fixes and a repair for a v26.06.8 regression that could throttle peer messages and delay channel traffic on busy nodes. The update also force-closes channels when an HTLC deadline expires during shutdown, protecting forwarded funds if payment is fulfilled late. Other fixes tighten rune authorization limits, mask sensitive configuration values, and prevent configuration-line injection. Maintainers recommend upgrading, particularly for operators on v26.06.8. Security tests are temporarily withheld to make exploit development harder and allow time to update.