← All advisories
T3 · Low

LND Panic on Malformed DNS Seed Response

Published September 21, 2026

Affected ProductAffected VersionsPatched Versions
lnd < 0.20.2-beta and 0.21.0-beta 0.20.2-beta, 0.21.1-beta

Impact

lnd’s DNS peer bootstrapper, enabled by default on mainnet, falls back to a TCP SRV lookup when the primary UDP query fails. The fallback accepted any response with a success code and then asserted that every answer record was an SRV record using Go’s single-value type assertion. A response containing any other record type, such as an A or CNAME record, caused an unrecovered panic in the bootstrap goroutine and terminated the daemon.

DNS is unauthenticated, so an on-path attacker, or a malicious or compromised DNS seed operator, could drop the UDP query to force the fallback and then return a crafted TCP response. The crash was repeatable whenever the node bootstrapped peers, at startup or whenever active peers fell below target.

There is no fund-loss path. The node restarts cleanly, although a persistently hostile seed would trigger the crash again at the next bootstrap. Operators who cannot upgrade can set nobootstrap=true to disable DNS peer bootstrapping.

Severity

Scored against the Lightning Labs severity taxonomy:

Dimension Score Reasoning
Impact Low Process crash, operator-recoverable by restart.
Attack Vector High Network. DNS is unauthenticated; no relationship with the victim is required.
Exploitability Med Requires an on-path position or control of a seed the victim queries, and the fallback path must be reached.
Virality Med A compromised seed serves the same crafted answer to every node that falls back to it, a replayable template; an on-path attacker reaches only the nodes on that path. Nothing propagates node to node.

Result: T3. Rule 3 (Impact = Low, base T3); no promotion because Virality is not High.

Patches

Fixed via lnd#10914 and released on both maintained lines: v0.21.1-beta (2026-06-30) and v0.20.2-beta (2026-07-08). Users should update to the patched release on their line.

Disclosure timeline

  • Identified internally by the Lightning Labs security team.
  • Fix merged 2026-06-24; released in lnd v0.21.1-beta on 2026-06-30 and v0.20.2-beta on 2026-07-08.
  • Public disclosure: 2026-09-21.