This release fixes one critical security issue. We recommend node operators update to 4.4.1.
Security
- Reject V5 transparent inputs signed with
SIGHASH_SINGLE(orSIGHASH_SINGLE|ANYONECANPAY) when the input has no transparent output at the same index (GHSA-pvmv-cwg8-v6c8). Follow-up to GHSA-cwfq-rfcr-8hmp.
Thanks to @sangsoo-osec, @zmanian, and @fivelittleducks for reporting the issue.