{
  "version": 1,
  "event_id": "evt_8d3b39b63a3e48c3",
  "url": "https://xiyu.news/events/evt_8d3b39b63a3e48c3/",
  "json": "https://xiyu.news/api/events/evt_8d3b39b63a3e48c3.json",
  "type": "other",
  "status": "developing",
  "category": "crypto",
  "title": {
    "zh": "Core Lightning 建议节点运营者因未修补漏洞下线",
    "en": "Core Lightning Advises Node Operators to Go Offline Over Unpatched Vulnerability"
  },
  "current_state": {
    "zh": "Core Lightning 运营商仍需修复未修补的漏洞，现在需检查 Docker 镜像摘要以确认修补是否到位，并计划于 9 月 11 日公开披露。",
    "en": "Core Lightning operators still need to address the unpatched vulnerability, now with added instructions to verify Docker image digests, with source disclosure planned for Sept. 11."
  },
  "first_seen_at": "2026-08-27T08:00:00+08:00",
  "last_updated_at": "2026-09-09T09:04:47.363343+00:00",
  "last_material_change_at": "2026-09-09T09:04:47.363343+00:00",
  "confidence": 0.75,
  "updates_count": 2,
  "sources_count": 2,
  "entities": [
    "advises",
    "core",
    "core-lightning",
    "docker",
    "lightning",
    "node",
    "offline",
    "operators",
    "over",
    "unpatched",
    "vulnerability"
  ],
  "identifiers": [],
  "topics": [
    "core-lightning",
    "docker",
    "lightning",
    "vulnerability"
  ],
  "updates": [
    {
      "update_id": "upd_57cf900c7d0ee486",
      "event_id": "evt_8d3b39b63a3e48c3",
      "occurred_at": "2026-08-27T08:00:00+08:00",
      "published_at": "2026-08-27T08:00:00+08:00",
      "first_seen_at": "2026-08-27T08:00:00+08:00",
      "time_precision": "edition",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "Core Lightning 建议节点运营者因未修补漏洞下线",
      "title_en": "Core Lightning Advises Node Operators to Go Offline Over Unpatched Vulnerability",
      "what_changed_zh": "Core Lightning 建议节点运营者因未修补漏洞下线",
      "what_changed_en": "Core Lightning Advises Node Operators to Go Offline Over Unpatched Vulnerability",
      "current_state_zh": "Core Lightning 建议节点运营者因未修补漏洞下线",
      "current_state_en": "Core Lightning Advises Node Operators to Go Offline Over Unpatched Vulnerability",
      "detailed_summary_zh": "Core Lightning（CLN）开发者已告知节点运营者让其节点下线，因为存在一个严重且尚未修补的漏洞。修复后的二进制文件尚未发布，细节目前处于两周的保密期（embargo）内。\n\n此事很重要，因为CLN是负责处理比特币支付的闪电网络（Lightning Network）的主要实现之一。如果漏洞在修复程序广泛部署前被利用，可能会危及用户资金以及人们对闪电网络的信任。\n\n无法升级的运营者被建议使用 --offline 标志运行节点。CLN 团队尚未披露漏洞细节，理由是两周的保密期，且官方修复版二进制文件尚未发布。",
      "detailed_summary_en": "Core Lightning (CLN) developers have told node operators to take their nodes offline because of a critical unpatched vulnerability. The fixed binaries have not yet been released, and details are under a two-week embargo.\n\nThis matters because CLN is one of the main implementations of the Lightning Network, which handles Bitcoin payments. An unpatched vulnerability could endanger users' funds and trust in the Lightning Network if exploited before fixes are widely deployed.\n\nOperators who cannot upgrade are advised to run nodes with the --offline flag. The CLN team has not disclosed vulnerability specifics, citing a two-week embargo, and official patched binaries are not yet available.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 8.5,
      "references": [],
      "confidence": 0.75,
      "story_ids": [
        "rss:thedefiant.io_api_feed:8b1158c0649fa554"
      ],
      "sources": [
        {
          "url": "https://thedefiant.io/news/security/core-lightning-tells-node-operators-to-go-offline-with-no-patch-published",
          "label": "The Defiant",
          "source_type": "rss",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_fcbe0642c9488519",
      "event_id": "evt_8d3b39b63a3e48c3",
      "occurred_at": "2026-09-09T08:30:48Z",
      "published_at": "2026-09-09T08:30:48Z",
      "first_seen_at": "2026-09-09T09:04:47.363343Z",
      "time_precision": "published",
      "update_type": "response",
      "material_change": true,
      "title_zh": "Bitcoin Core Lightning 的 Docker 漏洞使节点运营者暴露在风险中，尽管显示的是已更新版本",
      "title_en": "Bitcoin Core Lightning Docker bug leaves node operators exposed despite showing updated version",
      "what_changed_zh": "披露 Kubernetes 构建错误导致四个 Docker 标签分发了未修补的二进制文件，即使启动时显示为 v26.06.7，要求运营商验证镜像摘要并更换受影响的镜像。",
      "what_changed_en": "Disclosed a Docker build error distributing unpatched binaries under four tags that reported v26.06.7 at startup, requiring operators to verify image digests and replace affected images.",
      "current_state_zh": "Core Lightning 运营商仍需修复未修补的漏洞，现在需检查 Docker 镜像摘要以确认修补是否到位，并计划于 9 月 11 日公开披露。",
      "current_state_en": "Core Lightning operators still need to address the unpatched vulnerability, now with added instructions to verify Docker image digests, with source disclosure planned for Sept. 11.",
      "detailed_summary_zh": "Core Lightning Docker tags distributed unpatched binaries while reporting v26.06.7, requiring operators to verify image digests and replace faulty images before fixes become public.",
      "detailed_summary_en": "Core Lightning Docker tags distributed unpatched binaries while reporting v26.06.7, requiring operators to verify image digests and replace faulty images before fixes become public.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.5,
      "references": [],
      "confidence": 0.95,
      "story_ids": [
        "rss:cryptoslate.com_feed_:fad8b8ca05ade2e0"
      ],
      "sources": [
        {
          "url": "https://cryptoslate.com/bitcoin-core-lightning-docker-bug-leaves-node-operators-exposed-despite-showing-updated-version/",
          "label": "CryptoSlate",
          "source_type": "rss",
          "official": false
        }
      ]
    }
  ]
}
