Bitcoin Core escapes newlines so RPC input can no longer forge log lines
Bitcoin Core merged pull request #35833 on 30 September, closing a way to forge entries in the node's log. The change, by contributor l0rinc, touches four files: the logging code, a unit test and two functional tests.
The problem, as the pull request describes it: restricted RPC users, and callers of createwallet or restorewallet, could get a newline into the log through the name of a rejected RPC method or a wallet name. Core's general log escaping preserved newlines, so whatever followed the line break appeared as a separate entry, with its own timestamp, looking like a message from the node itself.
The pull request includes a reproducer. A node is started with an RPC whitelist that allows only getblock and stop. A call is made whose method name is getblock, a newline, and then a fabricated line reading like a block validation failure, ERROR: ConnectTip: ConnectBlock … failed, bad-txns-inputs-missingorspent. Before the fix, debug.log showed the expected warning that the user may not call the method, followed by the forged error as if it were a real event. After the fix, the same input stays on one line, with the newline rendered as \x0a.
The fix is narrow: newlines embedded in log messages are escaped. The functional tests for the RPC whitelist and wallet startup now check both input paths.

Why it matters
Operators and monitoring tools read debug.log to decide whether a node is healthy. A forged consensus error could send someone chasing a problem that does not exist, or bury a real one. The attacker still needed some RPC access, but restricted RPC users are exactly the accounts operators hand out to less-trusted services.