# BTCPay Server 2.4.5 Blocks Private-Network Requests by Default

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/27107
Published: 2026-10-06T17:40:32.000Z
Updated: 2026-10-06T17:40:32.000Z
Section: Technology

> The release also tightens refund permissions and speeds invoice creation by skipping unnecessary Lightning and fee lookups.

BTCPay Server 2.4.5 blocks outbound requests to private network destinations by default, adding a security control that affects merchants and developers who connect the payment processor to private services.

The change is intended to reduce server-side request forgery risks, in which a server is induced to contact systems that should not be reachable from outside. Operators who need private destinations for Lightning connections, LNURL requests, invoice notifications or webhooks may need to add exceptions.

The update also changes refund permissions. Employees who cannot create approved pull payments can no longer automatically approve refunds for invoice overpayments. Public invoice checkout, status and receipt information becomes hidden after monitoring ends, though users with invoice-view permission retain access.

Invoice creation is faster because the software skips unnecessary Lightning node and on-chain fee lookups. The release does not quantify the speed improvement.

Developers should review the breaking changes before upgrading. The release marks invoice notification URLs for deprecation, points developers to webhooks, and removes the URL field from manual invoice creation.
