The Lightning Network Daemon Project maintains the reference implementation of the Lightning Network, a layer-two payment protocol that operates on top of Bitcoin and other blockchains to enable fast, low-cost micropayments. Its vulnerability footprint centers on the daemon itself and reflects protocol-level and resource-management issues such as improper validation of integrity checks, uncontrolled resource allocation, and input-validation gaps that are typical of peer-to-peer network software. Live severity, exploitation status, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lightning Network Daemon Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-44797CRITICAL btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witness size checking. | Nov 7, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-41593HIGH Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure. | Oct 4, 2021 | 8.6 | 28 | NO | NO |
CVE-2020-26896HIGH Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the correspo | Oct 21, 2020 | 8.2 | 27 | NO | NO |
CVE-2022-39389MEDIUM Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that c | Nov 17, 2022 | 6.5 | 22 | NO | NO |
CVE-2020-26895MEDIUM Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can | Oct 21, 2020 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lightning Network Daemon Project.
Media articles that mention a CVE ID that affects a product developed by Lightning Network Daemon Project — matched by CVE ID, not by vendor name.