Core Lightning issues an urgent security update

Blockstream released Core Lightning 26.06.7, addressing confirmed vulnerabilities reported over the preceding three weeks. Signed binaries were made available immediately, while publication of the corresponding source was scheduled for 11 September.

The two-week delay is intended to give operators time to install the fixes before the changed code makes the underlying flaws easier to identify. Blockstream asked users to verify binary signatures and, once source becomes available, rebuild it to check that it matches the installed release.

For operators unable to upgrade immediately, the team described an offline mode that stops peer messages while continuing to monitor the blockchain. Releases older than 26.06.7 are no longer supported; the next scheduled feature release remains due in late September.

The response trades immediate source visibility for an upgrade window, making the promised later reproducibility check an important part of the release process.