<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T04:05:38.480179+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-355211</id>
    <title>EUVD-2026-355211</title>
    <updated>2026-10-05T04:05:38.525935+00:00</updated>
    <content>EUVD-2026-355211</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-355211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52736</id>
    <title>fkie_cve-2026-52736</title>
    <updated>2026-10-05T04:05:38.525968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the attacker to mutate coinbase scriptSig authentication data while retaining the transaction identifiers, merkle root, and block header hash, so the poisoned body fails later commitment validation but shares the canonical hash. In zebra-state/src/service.rs, queue_and_commit_to_non_finalized_state recorded the hash in non_finalized_block_write_sent_hashes before contextual validation completed and did not remove it when the write task rejected the body. When the honest body later arrived, the cached hash caused KnownBlock::WriteChannel duplicate handling to suppress it, leaving the node stuck one height behind until restart or reorganization. This issue is fixed in version 4.5.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-52736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4m69-67m6-prqp</id>
    <title>GHSA-4m69-67m6-prqp — Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache</title>
    <updated>2026-10-05T04:05:38.526003+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: zebra-state, crates.io: zebrad</p>
<p>## Description</p>
<p>### Am I affected</p>
<p>You are affected if:</p>
<p>1. You run any version of `zebrad` up to and including `v4.4.1`.
2. Your node accepts inbound P2P connections (`network.listen_addr` is set, which is the default).
3. Your node processes blocks past the checkpoint height (non-finalized state is active).</p>
<p>All default configurations are affected.</p>
<p>### Summary</p>
<p>Zebra records a block hash in `non_finalized_block_write_sent_hashes` when the block is sent to the write task, before contextual validation completes. If validation fails, the hash is not removed. A remote unauthenticated peer can deliver a poisoned block body that shares a header hash with a later valid canonical block. The poisoned body is rejected, but the hash remains cached. When the valid canonical block arrives, Zebra treats it as a duplicate and rejects it. The node cannot advance past that height until restart or a reorg event.</p>
<p>### Details</p>
<p>ZIP-244 defines `txid_v5` without binding transparent input `scriptSig`, which lives in `auth_digest` and is committed to by `hashBlockCommitments` in the block header. Because `merkle_root` is computed over txids (not auth digests), and the block hash is computed over the header, an attacker can construct two blocks with identical header hashes but different transaction bodies by mutating the coinbase scriptSig.</p>
<p>The attack flow over P2P:</p>
<p>1. Attacker observes a new block header (from any peer).
2. Attacker constructs a poisoned body by flipping a byte of the coinbas…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4m69-67m6-prqp"/>
  </entry>
</feed>
