{"id":"PYSEC-2026-1580","summary":"LNbits improperly handles potential network and payment failures when using Eclair backend","details":"### Summary\n\nPaying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight.\n\n### Details\n\nUsing `blocking: true` on the API call will lead to a timeout error if a payment does not get settled in the 30s timeout with the error: `Ask timed out on [Actor[akka://eclair-node/user/$l#134241942]] after [30000 ms]. Message of type [fr.acinq.eclair.payment.send.PaymentInitiator$SendPaymentToNode]. A typical reason for AskTimeoutException is that the recipient actor didn't send a reply.`\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L138\n\nThis is considered a payment failure by parts of the code, and assumes the payment is not going to be settled after:\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L144\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L141\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L146\n\nThe best way to fix this is to check the payment status after an error, and when not sure, always consider a payment still in flight.\n\n### PoC\n\nA very simple way to exploit this is:\n- Create a hold invoice\n- Pay the invoice with the LNbits server backed by an Eclair node, until it times out\n- Settle the hold invoice\n\n### Impact\n\nThis vulnerability can lead to a total loss of funds for the node backend.\n","aliases":["CVE-2024-34694","GHSA-3j4h-h3fp-vwww"],"modified":"2026-07-07T17:46:55.139639205Z","published":"2026-07-07T14:34:34.796839Z","references":[{"type":"WEB","url":"https://github.com/lnbits/lnbits/security/advisories/GHSA-3j4h-h3fp-vwww"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34694"},{"type":"PACKAGE","url":"https://github.com/lnbits/lnbits"},{"type":"PACKAGE","url":"https://pypi.org/project/lnbits"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3j4h-h3fp-vwww"}],"affected":[{"package":{"name":"lnbits","ecosystem":"PyPI","purl":"pkg:pypi/lnbits"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.6"}]}],"versions":["0.10.3.dev1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/lnbits/PYSEC-2026-1580.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}