ElementsProject/lightning
Releases243
Frequency2 weeks 2 days
Last Release
Stars3.08K
Core Lightning — Lightning Network implementation focusing on spec compliance and performance
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| — | 9.4 CRITICAL | 7.5 HIGH | ||
Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure. | ||||
| all versions | 6.3 MEDIUM | 3.5 LOW | ||
This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller. | ||||
| — | 7.5 HIGH | 5 MEDIUM | ||
c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds." | ||||