Lightning Network Daemon Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-38359

    Lightning Network Daemon Onion Bomb

    Last Modified: Apr 15, 2026
    Published: Jun 20, 2024

    CVE-2022-39389

    Witness Block Parsing DoS Vulnerability in lnd

    Last Modified: Apr 22, 2025
    Published: Nov 17, 2022

    CVE-2022-44797

    btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witness size checking.

    Last Modified: May 01, 2025
    Published: Nov 07, 2022

    CVE-2021-41593

    Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure.

    Last Modified: Nov 21, 2024
    Published: Oct 04, 2021

    CVE-2020-26896

    Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collision with an invoice, the preimage for an expected payment was instead released. A malicious peer could have deliberately intercepted an HTLC intended for the victim node, probed the preimage through a colluding relayed HTLC, and stolen the intercepted HTLC. The impact is a loss of funds in certain situations, and a weakening of the victim's receiver privacy.

    Last Modified: Nov 21, 2024
    Published: Oct 21, 2020
    Items Per Page