Security Advisories
Lightning Labs is committed to addressing security vulnerabilities in a timely and responsible manner. We work with security researchers to verify and address any potential vulnerabilities that are reported to us.
This page summarizes our policies in relation to disclosing vulnerabilities in our products, as well as provides a list of historical security advisories. To report a vulnerability, please email security@lightning.engineering.
Vulnerabilities are classified into four tiers based on their worst-case impact and reachability.
Viral fund loss. One action drains many victims, or one exploit template replays across them at negligible marginal cost per victim.
Targeted fund loss, or invalidated liveness.
Viral DoS, or fund loss whose trigger is rare.
Reachable but non-viral DoS, operator-recoverable.
The Severity Taxonomy page describes the four scoring dimensions, the tier rules, and the criteria we apply to decide whether a finding is a security vulnerability at all. Tier assignment is at Lightning Labs' discretion.
Our Software Life Cycle policy states which LND release lines receive security fixes, when a line reaches end of life, and when the advisory for a fixed vulnerability is published. In short: the two most recent major release lines are maintained, and a line reaches end of life the day the second major release after it ships.
-
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND Validation Barrier Map Leak via ChannelAnnouncement Spam
Any peer, with no prior channel relationship, could exhaust a victim lnd node’s memory by spamming channel_announcement messages. The gossiper’s validation barrier initializes i...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T1 · High Fix Date: 2024-09-12; Disclosure Date: 2026-08-11
LND update_fee Breach Fee-Burn Exploit
A channel initiator could cause a victim to recover little or nothing from a breach transaction by manipulating update_fee immediately before executing a fraudulent close.
lnd: affected < 0.18.3-beta lnd: patched in 0.18.3-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND query_short_chan_ids Gossip Queue Out-of-Memory
Any peer, with no prior channel relationship, could exhaust a victim lnd node’s memory by sending a flood of query_short_chan_ids gossip messages. Two compounding buffers amplif...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T1 · High Fix Date: 2024-05-30; Disclosure Date: 2026-08-11
LND Pending Commitment Excessive HTLC Failback Exploit
An attacker with a direct channel to a victim lnd node could steal the value of one or more in-flight HTLCs by combining an available denial-of-service vector with a race condit...
lnd: affected < 0.18.0-beta lnd: patched in 0.18.0-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND P2P Connection Flooding File-Descriptor Exhaustion
An attacker could exhaust a victim lnd node’s available file descriptors by opening a large number of inbound connections that do not correspond to any shared channel. Because l...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T1 · High Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND HTLC First-Stage Sweep Failure Due to Wallet Budget Constraint
An anchor-channel peer could prevent a victim lnd node from recovering the value of outgoing HTLCs after a force close.
lnd: affected >= 0.18.0-beta, < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND Gossip ChannelUpdate Suppression via Validation Barrier Poisoning
Any peer, with no prior channel relationship, could suppress a victim lnd node’s processing of channel_update or node_announcement messages for a targeted short channel ID (SCID...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2024-09-12; Disclosure Date: 2026-08-11
LND gossip_timestamp_filter Goroutine Exhaustion DoS
Any peer, with no prior channel relationship, could crash a victim lnd node by repeatedly sending gossip_timestamp_filter messages. When lnd receives a gossip_timestamp_filter, ...
lnd: affected < 0.18.3-beta lnd: patched in 0.18.3-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND Gossip Query Denial of Service
A peer could render a victim lnd node unresponsive by sending a large volume of gossip query messages. Without per-peer connection limits or bytes-based rate limiting on gossip ...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND ChannelReestablish Message Queue Out-of-Memory
A peer with pending channels open against a victim lnd node could exhaust the node’s heap memory by spamming channel_reestablish messages. Each connection’s chanMsgStream holds ...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2026-02-12; Disclosure Date: 2026-06-18
LND Gossip Nil-Map Panic on Zero-Timestamp Messages
An unauthenticated peer could crash a victim lnd node by sending a channel_update or node_announcement carrying a timestamp of 0. In the gossiper’s announcement de-duplication p...
lnd: affected < 0.20.1-beta lnd: patched in 0.20.1-beta Read advisory → -
T3 · Low Fix Date: 2023-10-03; Disclosure Date: 2024-06-20
LND Onion Bomb
A parsing vulnerability in lnd’s onion processing logic led to a DoS vector due to excessive memory allocation.
lnd: affected < 0.17.0-beta lnd: patched in 0.17.0-beta Read advisory → -
T1 · High Fix Date: 2022-11-01; Disclosure Date: 2022-11-17
Witness Block Parsing DoS Vulnerability
All lnd nodes before version v0.15.4 are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can co...
btcd: affected < v0.23.3 btcd: patched in v0.23.3 lnd: affected < v0.15.4-beta lnd: patched in v0.15.4-beta Read advisory →