Core Lightning 26.06.9 ships more security fixes and undoes a gossip throttle
Core Lightning released v26.06.9 on 7 October, a point release the maintainers strongly recommend upgrading to. It combines bug fixes, fixes for vulnerabilities responsibly reported by several sources, and a repair for a regression introduced in the previous release.
No embargo, tests withheld. As with 26.06.8, the fixes are public immediately, with no embargo period. The team has again temporarily withheld the tests for the security fixes, to make it harder to turn them quickly into working exploits and to give operators more time to upgrade before technical detail is published.
Where the security fixes are. Channel reestablishment, splicing, HTLC handling during shutdown, onion handling, onchaind, gossip range queries, runes and setconfig, plus several remote-crash and hardening fixes.
The regression. In 26.06.8, busy nodes could throttle their peers on ordinary gossip, pings and onion messages, delaying channel traffic. In 26.06.9, only gossip queries count against the CPU budget.

New builds. Reproducible arm64 and armv7 binaries for Ubuntu 22.04, 24.04 and 26.04 join the existing amd64 builds, each architecture with its own signed SHA256SUMS manifest.
Operator notes.
- A rune with restrictions can no longer create an unrestricted rune or relist blacklisted runes; those actions now need an unrestricted rune, and
invokeruneanddestroyruneare checked likecreateruneandblacklistrune. listconfigsnow prints...instead of the values ofwallet,recoverandtor-service-password.
This is the third security point release in the 26.06 line since late August; the 28 August release fixed a revoked-commitment penalty bug under a two-week embargo.