Core Lightning, an open-source implementation of Bitcoin’s Lightning Network, has confirmed multiple software vulnerabilities and urged node operators to apply a forthcoming security patch.
The project said it had reviewed a high volume of AI-generated Common Vulnerabilities and Exposures reports and determined that several were valid. Core Lightning recommended that operators upgrade their nodes immediately, while also providing a temporary workaround for those unable to update immediately. Operators were advised to restart their nodes with the “--offline” flag, which prevents incoming, outgoing or routed payments but keeps the node operational for blockchain monitoring and channel closure responses.
Core Lightning clarified that upgrading remains the primary safeguard, with the offline mode serving as an interim measure until an update is applied. Once upgraded, operators were instructed to remove the offline flag to restore full functionality, as leaving it active would disconnect the node from the network.
The confirmed flaws are distinct from remote denial-of-service vulnerabilities disclosed in May and July, which were addressed in prior releases. Core Lightning has not disclosed the nature, severity or CVE identifiers of the new vulnerabilities, nor reported any instances of exploitation or financial losses associated with them.












