TFTC on Nostr: Core Lightning's security release shipped broken Docker images. v26.06.7 contains ...
Core Lightning's security release shipped broken Docker images.
v26.06.7 contains fixes for responsibly disclosed vulnerabilities. Source and technical details are being held for 14 days to give operators time to patch before attackers get a roadmap.
The signed tarballs are the release. Operators can verify checksums and maintainer signatures now. Source inspection and reproducible builds come later.
But the Docker images automatically published under elementsproject/lightningd:v26.06.7 and latest reported the correct version on startup without actually containing the security fixes. A version label is not an artifact.
Operators should use the signed tarballs, verify the signatures, restart lightningd, and not treat the current Docker tag as an upgrade while the warning remains on the release page.
Core Lightning says AI models are increasing the number and speed of security reports its maintainers must triage. Cheaper bug discovery means more reports for maintainers and more tools for attackers. Release integrity and operator verification become the bottlenecks.
A fix only matters if operators can verify that it reached the artifact they installed.
Published at
2026-08-31 21:28:23 UTCEvent JSON
{
"id": "ef6809ba7051532c98a02eeeff2f0ac4b90acd5289d82993076db42b2a2eac50",
"pubkey": "85bdb5875e113dcc99498b474636449882ee15a1c78154ab07c065b47339d672",
"created_at": 1788211703,
"kind": 1,
"tags": [
[
"imeta",
"url https://blossom.primal.net/ff294fc104e7a0f90567eefb541307ef837d93ade459137358dc265934ef4be4.jpg",
"m image/jpeg",
"x ff294fc104e7a0f90567eefb541307ef837d93ade459137358dc265934ef4be4",
"size 107477"
]
],
"content": "Core Lightning's security release shipped broken Docker images.\n\nv26.06.7 contains fixes for responsibly disclosed vulnerabilities. Source and technical details are being held for 14 days to give operators time to patch before attackers get a roadmap.\n\nThe signed tarballs are the release. Operators can verify checksums and maintainer signatures now. Source inspection and reproducible builds come later.\n\nBut the Docker images automatically published under elementsproject/lightningd:v26.06.7 and latest reported the correct version on startup without actually containing the security fixes. A version label is not an artifact.\n\nOperators should use the signed tarballs, verify the signatures, restart lightningd, and not treat the current Docker tag as an upgrade while the warning remains on the release page.\n\nCore Lightning says AI models are increasing the number and speed of security reports its maintainers must triage. Cheaper bug discovery means more reports for maintainers and more tools for attackers. Release integrity and operator verification become the bottlenecks.\n\nA fix only matters if operators can verify that it reached the artifact they installed.\nhttps://blossom.primal.net/ff294fc104e7a0f90567eefb541307ef837d93ade459137358dc265934ef4be4.jpg",
"sig": "cae1d81a29d28ef8ad17b580de897f8c2990470bec7bb92b0bd0e697b12f05cba5d9a1ec91915ecffc8f02ce469e9bf5259ed622a440208f53b2bf565bf19342"
}