Description
LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1900 | LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6. |
Github GHSA |
GHSA-3j4h-h3fp-vwww | LNbits improperly handles potential network and payment failures when using Eclair backend |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:59:21.774Z
Reserved: 2024-05-07T13:53:00.131Z
Link: CVE-2024-34694
Updated: 2024-08-02T02:59:21.774Z
Status : Deferred
Published: 2024-06-14T15:15:50.637
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-34694
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:16:10Z
Weaknesses
EUVD
Github GHSA