ElementsProject/lightning

ElementsProject/lightning

Releases243
Frequency2 weeks 2 days
Last Release
Stars3.08K
Core Lightning — Lightning Network implementation focusing on spec compliance and performance

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
9.4 CRITICAL7.5 HIGH

Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.

all versions6.3 MEDIUM3.5 LOW

This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.

7.5 HIGH5 MEDIUM

c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds."