The newest Core Lightning upgrade clears up Bitcoin payment delays, safeguards funds when channels close, and patches security holes that impact node operators.
Core Lightning—software built to run Bitcoin Lightning payment nodes—just dropped version 26.06.9, packing security patches and a fix for a bug that could slow down channel traffic on busy nodes running version 26.06.8.
GitHub shows October 7 as the launch date for the fresh release, though its versioned changelog lists October 6.
This fresh release hands operators running v26.06.8 a new chance to upgrade, coming on the heels of the September 27 revoked-channel penalty flaw patched in v26.06.7. The newest patch bundles fixes while tackling a regression triggered by that subsequent version.
Bitcoin Payment Delays and Shutdown Risks Raise Concerns#
Maintainers point out that version 26.06.8 mistakenly lumped standard gossip, pings, and onion messages into a CPU budget meant strictly for gossip queries, which ended up throttling peers and slowing down channel traffic on active nodes.
Version 26.06.9 walls off that budget specifically for gossip queries, keeping routine messages from eating into it and clearing up that documented throttling issue. Maintainers note that this specific regression only targets active nodes running Core Lightning version 26.06.8.
The changelog also highlights a patch for a payment contract (HTLC) timing out mid-channel closure. Version 26.06.9 now forces the channel shut in that scenario, keeping operators from losing forwarded funds if the payment settles late.
Stay in the loop
Get crypto news before the market moves
Join thousands of investors who read our daily briefing.
No spam. Unsubscribe anytime.
For operators routing payments, this update clears up a funds-safety snag when payment deadlines and channel closures overlap.
Other patches lock down restrictions on authorization runes, meaning a limited rune can no longer spawn an unrestricted one or re-add blacklisted runes. Developers also extended those limits on creation and blocklisting methods to cover the invokerune and destroyrune aliases as well.
The listconfigs command now hides sensitive data—such as recovery details and Bitcoin RPC passwords—from every caller. Meanwhile, the setconfig command blocks a vulnerability that let attackers inject configuration lines through persistent option values.
These patches are ready to grab right now, though maintainers decided to hold back security tests for a bit to make exploit creation tougher and give operators a head start on upgrading.
Nodes running master code cannot roll back to a 26.06.x release because their database schema is too advanced. The update also reminds users that dual funding is still experimental, and it advises against setting up zero-confirmation channels with untrusted peers.
Maintainers strongly recommend that Core Lightning users—including anyone running v26.06.8—upgrade to v26.06.9 at their earliest convenience.



