Description
LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6.
Published: 2024-06-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-1900 LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight. This vulnerability can lead to a total loss of funds for the node backend. This vulnerability is fixed in 0.12.6.
Github GHSA Github GHSA GHSA-3j4h-h3fp-vwww LNbits improperly handles potential network and payment failures when using Eclair backend
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:59:21.774Z

Reserved: 2024-05-07T13:53:00.131Z

Link: CVE-2024-34694

cve-icon Vulnrichment

Updated: 2024-08-02T02:59:21.774Z

cve-icon NVD

Status : Deferred

Published: 2024-06-14T15:15:50.637

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-34694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:16:10Z

Weaknesses