Core Lightning, the software utilized to operate Bitcoin Lightning payment nodes, has rolled out version 26.06.9. This update includes security enhancements along with a patch for a regression that had the potential to slow down channel traffic on heavily utilized nodes operating on v26.06.8.
According to GitHub, the new version went live on Oct. 7, whereas its versioned changelog lists the date as Oct. 6.
Following the Sept. 27 revoked-channel penalty flaw resolved in v26.06.7, this latest release presents operators who previously installed v26.06.8 with a new upgrade choice. It incorporates additional fixes while also resolving a regression that was triggered by that subsequent version.
Bitcoin payment delays and shutdown risk
Maintainers noted that in v26.06.8, standard gossip, pings, and onion messages were incorrectly counted against a CPU budget that was specifically designated for gossip queries. On high-traffic nodes, this calculation could result in peer throttling and delayed channel traffic.
Version 26.06.9 dedicates that budget exclusively to gossip queries, ensuring that standard messages no longer draw from it and eliminating the documented reason for the throttling. The regression highlighted by the maintainers specifically impacts busy nodes running Core Lightning v26.06.8.
The changelog additionally outlines a correction for a payment contract (HTLC) that expires during a channel shutdown. In such scenarios, v26.06.9 now mandates a force-closure of the channel, protecting against the loss of forwarded funds should the payment be fulfilled belatedly.
For node operators who forward payments, this resolves a fund-security issue that arises when payment expiration times and channel closures coincide.
Additional patches enforce restrictions on runes used for call authorization, preventing a limited rune from generating an unrestricted counterpart or re-listing blacklisted runes. Furthermore, limitations applied to the relevant creation and blocklisting methods now extend to include the invokerune and destroyrune aliases.
The listconfigs command now hides multiple confidential items—such as Bitcoin RPC passwords and recovery data—from all callers. Meanwhile, the setconfig command plugs a vulnerability that allowed configuration lines to be injected via persistent option values.
While these patches are accessible right away, maintainers have chosen to temporarily withhold security tests to complicate exploit creation and provide node operators extra time to update their systems.
Nodes operating on the master branch are unable to downgrade to a 26.06.x release due to having a more recent database schema. Additionally, the release notes remind users that dual funding is still in an experimental phase and advise against employing zero-confirmation channels with untrusted peers.
Project maintainers strongly advise all Core Lightning users, including those currently on v26.06.8, to transition to v26.06.9 at the earliest opportunity.





