Core Lightning confirmed multiple security vulnerabilities in its Lightning Network node software after reviewing a large number of AI-generated CVE reports. Several submissions identified legitimate issues requiring fixes.
The project issued an advisory on August 27, 2026. It described an upgrade path to the signed release and the --offline flag as a temporary option for operators.
Technical details of the vulnerabilities remain undisclosed under a confidentiality embargo. No evidence of exploitation or associated losses has been reported.
This set of issues is separate from denial-of-service vulnerabilities disclosed earlier in 2026 that affected the connectd and gossipd components.
The influx of AI-generated reports shows how automated tools now contribute to vulnerability discovery in open-source cryptocurrency projects. Maintainers performed manual validation on the submissions.
What would falsify this reading: disclosure of specific affected components or evidence of active exploitation would alter the assessment of the situation.
Core Lightning project advisory