Lightning Network Daemon Project
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41593 | Hig | 0.56 | 8.6 | 0.02 | Oct 4, 2021 | Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure. | ||
| CVE-2020-26896 | Hig | 0.53 | 8.2 | 0.01 | Oct 21, 2020 | Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a… | ||
| CVE-2022-39389 | Hig | 0.46 | 8.2 | 0.01 | Nov 17, 2022 | Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can… | ||
| CVE-2020-26895 | Med | 0.35 | 5.3 | 0.01 | Oct 21, 2020 | Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing… |
- risk 0.56cvss 8.6epss 0.02
Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure.
- risk 0.53cvss 8.2epss 0.01
Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a…
- risk 0.46cvss 8.2epss 0.01
Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can…
- risk 0.35cvss 5.3epss 0.01
Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing…