---
id: CVE-2024-34694
aliases:
  - GHSA-3j4h-h3fp-vwww
  - PYSEC-2026-1580
title: >-
  LNbits improperly handles potential network and payment failures when using
  Eclair backend
summary: >-
  LNbits improperly handles potential network and payment failures when using
  Eclair backend
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
vendor: lnbits
product: lnbits
ecosystem: pip
affected:
  - lnbits < 0.12.6
patched:
  - lnbits 0.12.6
published: '2024-06-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-3j4h-h3fp-vwww'
references:
  - url: 'https://github.com/lnbits/lnbits/security/advisories/GHSA-3j4h-h3fp-vwww'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-34694'
  - url: 'https://github.com/lnbits/lnbits'
tags:
  - osv
  - pip
epss: 0.00602
epssPercentile: 0.46552
ingestedAt: '2026-07-08T18:25:44.925Z'
---

## Overview

### Summary

Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight.

### Details

Using `blocking: true` on the API call will lead to a timeout error if a payment does not get settled in the 30s timeout with the error: `Ask timed out on [Actor[akka://eclair-node/user/$l#134241942]] after [30000 ms]. Message of type [fr.acinq.eclair.payment.send.PaymentInitiator$SendPaymentToNode]. A typical reason for AskTimeoutException is that the recipient actor didn't send a reply.`
https://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L138

This is considered a payment failure by parts of the code, and assumes the payment is not going to be settled after:
https://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L144
https://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L141
https://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L146

The best way to fix this is to check the payment status after an error, and when not sure, always consider a payment still in flight.

### PoC

A very simple way to exploit this is:
- Create a hold invoice
- Pay the invoice with the LNbits server backed by an Eclair node, until it times out
- Settle the hold invoice

### Impact

This vulnerability can lead to a total loss of funds for the node backend.


## Affected packages

- `lnbits < 0.12.6`

## Remediation

Upgrade to a patched release:

- `lnbits 0.12.6`
