Security Advisories
Lightning Labs is committed to addressing security vulnerabilities in a timely and responsible manner. We work with security researchers to verify and address any potential vulnerabilities that are reported to us.
This page summarizes our policies in relation to disclosing vulnerabilities in our products, as well as provides a list of historical security advisories. To report a vulnerability, please email security@lightning.engineering — see Report a Vulnerability below for our PGP key.
Vulnerabilities are classified into four tiers based on their worst-case impact and reachability.
Viral fund loss. One action drains many victims, or one exploit template replays across them at negligible marginal cost per victim.
Targeted fund loss, or invalidated liveness.
Viral DoS, or fund loss whose trigger is rare.
Reachable but non-viral DoS, operator-recoverable.
The Severity Taxonomy page describes the four scoring dimensions, the tier rules, and the criteria we apply to decide whether a finding is a security vulnerability at all. Tier assignment is at Lightning Labs' discretion.
Our Software Life Cycle policy states which LND release lines receive security fixes, when a line reaches end of life, and when the advisory for a fixed vulnerability is published. In short: the two most recent major release lines are maintained, and a line reaches end of life the day the second major release after it ships.
-
T1 · High Fix Date: 2025-02-12; Disclosure Date: 2026-09-21
LND Invoice Marked Settled After HTLC Cancelled by Interceptor
A Lightning Terminal node running tapd with the invoice HTLC interceptor enabled, even with no asset channels open, could record an invoice as settled while the HTLC that paid i...
taproot assets: affected <= v0.5.0 taproot assets: patched in v0.5.1 lnd: affected 0.18.4-beta – 0.18.5-beta lnd: patched in 0.19.0-beta lightning terminal: affected < v0.15.0-alpha lightning terminal: patched in v0.15.0-alpha Read advisory → -
T3 · Low Fix Date: 2026-02-12; Disclosure Date: 2026-09-21
LND Gossip Stall via Malformed channel_announcement Flood
A peer could stall a victim node’s entire gossip pipeline by sending more than 1000 malformed channel_announcement messages. Each announcement was crafted so that node_id_1 equa...
lnd: affected 0.19.0-beta – 0.20.0-beta lnd: patched in 0.20.1-beta Read advisory → -
T3 · Low Fix Date: 2026-06-30; Disclosure Date: 2026-09-21
LND Panic on Malformed DNS Seed Response
lnd’s DNS peer bootstrapper, enabled by default on mainnet, falls back to a TCP SRV lookup when the primary UDP query fails. The fallback accepted any response with a success co...
lnd: affected < 0.20.2-beta and 0.21.0-beta lnd: patched in 0.20.2-beta, 0.21.1-beta Read advisory → -
T3 · Low Fix Date: 2025-11-20; Disclosure Date: 2026-09-21
LND Out-of-Memory via Brontide Write Allocations
lnd’s encrypted transport layer (Brontide) allocated fresh buffers on every message written. A peer that drove a high volume of message traffic could force enough allocation to ...
lnd: affected < 0.20.0-beta lnd: patched in 0.20.0-beta Read advisory → -
T3 · Low Fix Date: 2026-06-18; Disclosure Date: 2026-09-21
btcd Out-of-Memory via Oversized reject Messages
After the alert message was removed and the cfcheckpt limit was reduced in v0.25.0, the reject message still declared a maximum payload equal to the overall message limit of 32 ...
btcd: affected < v0.26.0 btcd: patched in v0.26.0 Read advisory → -
T3 · Low Fix Date: 2026-06-18; Disclosure Date: 2026-09-21
btcd Pre-Handshake Transaction Parser Panic
An unauthenticated remote host could crash btcd with a single crafted packet sent as the first message on a new connection, before any version handshake.
btcd: affected v0.24.0 – v0.25.0 btcd: patched in v0.26.0 Read advisory → -
T3 · Low Fix Date: 2025-11-04; Disclosure Date: 2026-09-21
btcd Out-of-Memory via 32 MB Message Payloads
btcd allowed individual P2P messages to carry payloads of up to roughly 32 MB, where Bitcoin Core caps messages at 4 MB. Two message types, alert and cfcheckpt, declared the ful...
btcd: affected < v0.25.0 btcd: patched in v0.25.0 Read advisory → -
T3 · Low Fix Date: 2026-07-24; Disclosure Date: 2026-09-21
btcd Inbound Transport Handshake Resource Exhaustion
btcd accepted an inbound TCP socket and ran the transport handshake before the connection counted against the server’s maxpeers limit. A remote host could therefore hold many in...
btcd: affected < v0.26.2 btcd: patched in v0.26.2 Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND Validation Barrier Map Leak via ChannelAnnouncement Spam
Any peer, with no prior channel relationship, could exhaust a victim lnd node’s memory by spamming channel_announcement messages. The gossiper’s validation barrier initializes i...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T1 · High Fix Date: 2024-09-12; Disclosure Date: 2026-08-11
LND update_fee Breach Fee-Burn Exploit
A channel initiator could cause a victim to recover little or nothing from a breach transaction by manipulating update_fee immediately before executing a fraudulent close.
lnd: affected < 0.18.3-beta lnd: patched in 0.18.3-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND query_short_chan_ids Gossip Queue Out-of-Memory
Any peer, with no prior channel relationship, could exhaust a victim lnd node’s memory by sending a flood of query_short_chan_ids gossip messages. Two compounding buffers amplif...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T1 · High Fix Date: 2024-05-30; Disclosure Date: 2026-08-11
LND Pending Commitment Excessive HTLC Failback Exploit
An attacker with a direct channel to a victim lnd node could steal the value of one or more in-flight HTLCs by combining an available denial-of-service vector with a race condit...
lnd: affected < 0.18.0-beta lnd: patched in 0.18.0-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND P2P Connection Flooding File-Descriptor Exhaustion
An attacker could exhaust a victim lnd node’s available file descriptors by opening a large number of inbound connections that do not correspond to any shared channel. Because l...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T1 · High Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND HTLC First-Stage Sweep Failure Due to Wallet Budget Constraint
An anchor-channel peer could prevent a victim lnd node from recovering the value of outgoing HTLCs after a force close.
lnd: affected >= 0.18.0-beta, < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND Gossip ChannelUpdate Suppression via Validation Barrier Poisoning
Any peer, with no prior channel relationship, could suppress a victim lnd node’s processing of channel_update or node_announcement messages for a targeted short channel ID (SCID...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2024-09-12; Disclosure Date: 2026-08-11
LND gossip_timestamp_filter Goroutine Exhaustion DoS
Any peer, with no prior channel relationship, could crash a victim lnd node by repeatedly sending gossip_timestamp_filter messages. When lnd receives a gossip_timestamp_filter, ...
lnd: affected < 0.18.3-beta lnd: patched in 0.18.3-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND Gossip Query Denial of Service
A peer could render a victim lnd node unresponsive by sending a large volume of gossip query messages. Without per-peer connection limits or bytes-based rate limiting on gossip ...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2025-05-22; Disclosure Date: 2026-08-11
LND ChannelReestablish Message Queue Out-of-Memory
A peer with pending channels open against a victim lnd node could exhaust the node’s heap memory by spamming channel_reestablish messages. Each connection’s chanMsgStream holds ...
lnd: affected < 0.19.0-beta lnd: patched in 0.19.0-beta Read advisory → -
T3 · Low Fix Date: 2026-02-12; Disclosure Date: 2026-06-18
LND Gossip Nil-Map Panic on Zero-Timestamp Messages
An unauthenticated peer could crash a victim lnd node by sending a channel_update or node_announcement carrying a timestamp of 0. In the gossiper’s announcement de-duplication p...
lnd: affected < 0.20.1-beta lnd: patched in 0.20.1-beta Read advisory → -
T3 · Low Fix Date: 2023-10-03; Disclosure Date: 2024-06-20
LND Onion Bomb
A parsing vulnerability in lnd’s onion processing logic led to a DoS vector due to excessive memory allocation.
lnd: affected < 0.17.0-beta lnd: patched in 0.17.0-beta Read advisory → -
T1 · High Fix Date: 2022-11-01; Disclosure Date: 2022-11-17
Witness Block Parsing DoS Vulnerability
All lnd nodes before version v0.15.4 are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can co...
btcd: affected < v0.23.3 btcd: patched in v0.23.3 lnd: affected < v0.15.4-beta lnd: patched in v0.15.4-beta Read advisory →
If you believe you have found a security vulnerability in a Lightning Labs product, please email us. Include a description of the issue, the affected product and version, and steps to reproduce if available. The PGP key below can be used to communicate sensitive information. Please do not report security vulnerabilities through public GitHub issues.