<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 22:47:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-355214</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-355214</link>
      <description>EUVD-2026-355214</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-355214</guid>
    </item>
    <item>
      <title>fkie_cve-2026-52731</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-52731</link>
      <description>&lt;p&gt;ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str originally checked the input byte length and then sliced fixed byte ranges to parse encoded fields. A slice boundary can land inside a multi-byte character and trigger Rust&amp;#39;s byte index is not a char boundary panic. Zebra release builds use panic equals abort, so one malformed authenticated RPC request terminates the entire node process and can be repeated after restart. This issue is fixed in version 4.5.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str originally checked the input byte length and then sliced fixed byte ranges to parse encoded fields. A slice boundary can land inside a multi-byte character and trigger Rust&amp;#39;s byte index is not a char boundary panic. Zebra release builds use panic equals abort, so one malformed authenticated RPC request terminates the entire node process and can be repeated after restart. This issue is fixed in version 4.5.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-52731</guid>
    </item>
    <item>
      <title>GHSA-qv2r-v3mx-f4pf — zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qv2r-v3mx-f4pf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: zebra-rpc, crates.io: zebrad&lt;/p&gt;
&lt;p&gt;### Am I affected&lt;/p&gt;
&lt;p&gt;You are affected if:&lt;/p&gt;
&lt;p&gt;1. You run `zebrad` up to and including `v4.4.1`.
2. Your `zebrad.toml` sets `rpc.listen_addr` to a TCP address (RPC server is enabled).
3. An attacker can authenticate to the RPC endpoint. With the default `enable_cookie_auth = true`, this requires the attacker to read the `.cookie` file. With `enable_cookie_auth = false`, any network client reaching the RPC port can trigger it.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `getblocktemplate` RPC handler panics when parsing a `LongPollId` parameter that contains non-ASCII (multi-byte UTF-8) characters. The handler performs byte-index string slicing on the user-supplied string, which panics in Rust when a byte index falls within a multi-byte character boundary. Because Zebra&amp;#39;s release profile sets `panic = &amp;#34;abort&amp;#34;`, the panic terminates the entire node process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `getblocktemplate` handler receives a user-supplied `LongPollId` string and slices it at fixed byte offsets to extract the encoded tip hash and tip height. When the string contains multi-byte UTF-8 characters, a byte-index slice can land in the middle of a character, causing Rust&amp;#39;s `str` indexing to panic with &amp;#34;byte index is not a char boundary.&amp;#34;&lt;/p&gt;
&lt;p&gt;Under the `panic = &amp;#34;abort&amp;#34;` release profile, this panic terminates the entire `zebrad` process rather than just the RPC task.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;zebra-rpc 8.0.0 and zebrad 4.5.0.&lt;/p&gt;
&lt;p&gt;Replace byte-index string slicing with character-aware parsing or validate that the `LongPollId` string contains only AS…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: zebra-rpc, crates.io: zebrad&lt;/p&gt;
&lt;p&gt;### Am I affected&lt;/p&gt;
&lt;p&gt;You are affected if:&lt;/p&gt;
&lt;p&gt;1. You run `zebrad` up to and including `v4.4.1`.
2. Your `zebrad.toml` sets `rpc.listen_addr` to a TCP address (RPC server is enabled).
3. An attacker can authenticate to the RPC endpoint. With the default `enable_cookie_auth = true`, this requires the attacker to read the `.cookie` file. With `enable_cookie_auth = false`, any network client reaching the RPC port can trigger it.&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `getblocktemplate` RPC handler panics when parsing a `LongPollId` parameter that contains non-ASCII (multi-byte UTF-8) characters. The handler performs byte-index string slicing on the user-supplied string, which panics in Rust when a byte index falls within a multi-byte character boundary. Because Zebra&amp;#39;s release profile sets `panic = &amp;#34;abort&amp;#34;`, the panic terminates the entire node process.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The `getblocktemplate` handler receives a user-supplied `LongPollId` string and slices it at fixed byte offsets to extract the encoded tip hash and tip height. When the string contains multi-byte UTF-8 characters, a byte-index slice can land in the middle of a character, causing Rust&amp;#39;s `str` indexing to panic with &amp;#34;byte index is not a char boundary.&amp;#34;&lt;/p&gt;
&lt;p&gt;Under the `panic = &amp;#34;abort&amp;#34;` release profile, this panic terminates the entire `zebrad` process rather than just the RPC task.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;zebra-rpc 8.0.0 and zebrad 4.5.0.&lt;/p&gt;
&lt;p&gt;Replace byte-index string slicing with character-aware parsing or validate that the `LongPollId` string contains only AS…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qv2r-v3mx-f4pf</guid>
    </item>
  </channel>
</rss>
