Search
Find a vulnerability
Search criteria
82 vulnerabilities by ZcashFoundation
CVE-2026-104437 (GCVE-0-2026-104437)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling
Summary
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Severity
CWE
- CWE-347 - Improper Verification of Cryptographic Signature
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 4.4.0
(semver)
Unaffected: 4.4.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-05-02 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.4.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.4.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sangsoo-osec"
},
{
"lang": "en",
"type": "reporter",
"value": "defuse"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-05-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:13.855Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-cwfq-rfcr-8hmp)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-cwfq-rfcr-8hmp"
},
{
"name": "VulnCheck Advisory: Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-4.4.0-consensus-split-via-sighash-single-missing-output-handling"
}
],
"title": "Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104437",
"datePublished": "2026-10-02T11:38:13.855Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:13.855Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104436 (GCVE-0-2026-104436)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length
Summary
Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.
Severity
CWE
- CWE-770 - Allocation of Resources Without Limits or Throttling
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 4.5.0
(semver)
Unaffected: 4.5.0 (semver) |
|
| ZcashFoundation | zebra |
Affected:
0 , < 8.0.0
(semver)
Unaffected: 8.0.0 (semver) |
Date Public
2026-05-29 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.5.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-chain",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "8.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "dingledropper"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
}
],
"datePublic": "2026-05-29T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:13.172Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-443g-gwgp-49x4)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-443g-gwgp-49x4"
},
{
"name": "VulnCheck Advisory: Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-4.5.0-cpu-amplification-via-uncapped-getblocks-getheaders-locator-length"
}
],
"title": "Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104436",
"datePublished": "2026-10-02T11:38:13.172Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:13.172Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104435 (GCVE-0-2026-104435)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output
Summary
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Severity
CWE
- CWE-347 - Improper Verification of Cryptographic Signature
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-4.4.0-… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
4.4.0 , < 4.4.1
(semver)
Unaffected: 4.4.1 (semver) |
|
| ZcashFoundation | zebra |
Affected:
6.0.0 , < 6.0.1
(semver)
Unaffected: 6.0.1 (semver) |
Date Public
2026-05-04 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.4.1",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.4.1",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-script",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.0.1",
"status": "affected",
"version": "6.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.0.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.4.1",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.1",
"versionStartIncluding": "6.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sangsoo-osec"
},
{
"lang": "en",
"type": "reporter",
"value": "fivelittleducks"
}
],
"datePublic": "2026-05-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:12.487Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-pvmv-cwg8-v6c8)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-pvmv-cwg8-v6c8"
},
{
"name": "VulnCheck Advisory: Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-4.4.0-consensus-divergence-via-v5-sighash-single-without-output"
}
],
"title": "Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104435",
"datePublished": "2026-10-02T11:38:12.487Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:12.487Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104434 (GCVE-0-2026-104434)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC
Summary
ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.
Severity
CWE
- CWE-617 - Reachable Assertion
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 8.0.0
(semver)
Unaffected: 8.0.0 (semver) |
|
| ZcashFoundation | zebra |
Affected:
0 , < 4.5.0
(semver)
Unaffected: 4.5.0 (semver) |
Date Public
2026-05-29 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-rpc",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "8.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.5.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "8.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "robustfengbin"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-05-29T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-617",
"description": "Reachable Assertion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:11.845Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-c8w6-x74f-vmg3)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-c8w6-x74f-vmg3"
},
{
"name": "VulnCheck Advisory: Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-8.0.0-denial-of-service-via-z-listunifiedreceivers-rpc"
}
],
"title": "Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104434",
"datePublished": "2026-10-02T11:38:11.845Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:11.845Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104432 (GCVE-0-2026-104432)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response
Summary
Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.
Severity
5.3 (Medium)
CWE
- CWE-754 - Improper Check for Unusual or Exceptional Conditions
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.3.0
(semver)
Unaffected: 6.3.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-08-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/Zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.3.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Maakai123"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
}
],
"datePublic": "2026-08-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-754",
"description": "Improper Check for Unusual or Exceptional Conditions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:11.214Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-h8m8-844p-v3m9)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-h8m8-844p-v3m9"
},
{
"name": "VulnCheck Advisory: Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-false-readiness-via-discarded-one-hash-findblocks-response"
}
],
"title": "Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104432",
"datePublished": "2026-10-02T11:38:11.214Z",
"dateReserved": "2026-10-02T00:50:26.603Z",
"dateUpdated": "2026-10-02T11:38:11.214Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104431 (GCVE-0-2026-104431)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification
Summary
Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.
Severity
CWE
- CWE-405 - Asymmetric Resource Consumption (Amplification)
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.0.0
(semver)
Unaffected: 6.0.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-13 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ouicate"
},
{
"lang": "en",
"type": "finder",
"value": "conradoplg"
}
],
"datePublic": "2026-07-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-405",
"description": "Asymmetric Resource Consumption (Amplification)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:10.560Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-84j3-rw4c-gqmj)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-84j3-rw4c-gqmj"
},
{
"name": "VulnCheck Advisory: Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.0.0-denial-of-service-via-synchronous-script-ffi-verification"
}
],
"title": "Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104431",
"datePublished": "2026-10-02T11:38:10.560Z",
"dateReserved": "2026-10-02T00:50:26.603Z",
"dateUpdated": "2026-10-02T11:38:10.560Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104430 (GCVE-0-2026-104430)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount
Summary
Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.
Severity
CWE
- CWE-628 - Function Call with Incorrectly Specified Arguments
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-4.5.0-… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
4.5.0 , < 4.5.1
(semver)
Unaffected: 4.5.1 (semver) |
|
| ZcashFoundation | zebra |
Affected:
7.0.0 , < 7.0.1
(semver)
Unaffected: 7.0.1 (semver) |
Date Public
2026-06-01 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.5.1",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.5.1",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-script",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "7.0.1",
"status": "affected",
"version": "7.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.0.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.5.1",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.1",
"versionStartIncluding": "7.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sangsoo-osec"
}
],
"datePublic": "2026-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd\u0027s accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra\u0027s inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-628",
"description": "Function Call with Incorrectly Specified Arguments",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:09.916Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-2prc-cj5x-4443)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2prc-cj5x-4443"
},
{
"name": "VulnCheck Advisory: Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-4.5.0-consensus-split-via-p2sh-sigop-overcount"
}
],
"title": "Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104430",
"datePublished": "2026-10-02T11:38:09.916Z",
"dateReserved": "2026-10-02T00:50:26.603Z",
"dateUpdated": "2026-10-02T11:38:09.916Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104429 (GCVE-0-2026-104429)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 12:27
VLAI
EPSS
VEX
Title
Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages
Summary
Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 12:27 UTC
CWE
- CWE-770 - Allocation of Resources Without Limits or Throttling
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.0.0-rc.0
(semver)
Unaffected: 6.0.0-rc.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-03 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104429",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T12:27:13.306414Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T12:27:23.589Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.0.0-rc.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.0.0-rc.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.0-rc.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "SuplabsYi"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
}
],
"datePublic": "2026-07-03T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers\u0027 transaction relay."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:09.257Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-m9xx-8rcj-vmgp)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-m9xx-8rcj-vmgp"
},
{
"name": "VulnCheck Advisory: Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.0.0-rc.0-per-peer-mempool-admission-bypass-via-p2p-tx-messages"
}
],
"title": "Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104429",
"datePublished": "2026-10-02T11:38:09.257Z",
"dateReserved": "2026-10-02T00:46:23.831Z",
"dateUpdated": "2026-10-02T12:27:23.589Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104428 (GCVE-0-2026-104428)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 11.0.0 Denial of Service via getblock Verbosity 2
Summary
The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.
Severity
5.3 (Medium)
CWE
- CWE-617 - Reachable Assertion
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 11.0.0
(semver)
Unaffected: 11.0.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-03 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-rpc",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "11.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "11.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "11.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "reporter",
"value": "defuse"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-07-03T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation\u0027s Zebra node, panics on verbosity 2 for a side-chain block because the block\u0027s -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-617",
"description": "Reachable Assertion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:08.558Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-x6v8-c2xp-928m)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-x6v8-c2xp-928m"
},
{
"name": "VulnCheck Advisory: Zebra before 11.0.0 Denial of Service via getblock Verbosity 2",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-11.0.0-denial-of-service-via-getblock-verbosity-2"
}
],
"title": "Zebra before 11.0.0 Denial of Service via getblock Verbosity 2",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104428",
"datePublished": "2026-10-02T11:38:08.558Z",
"dateReserved": "2026-10-02T00:46:23.831Z",
"dateUpdated": "2026-10-02T11:38:08.558Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104427 (GCVE-0-2026-104427)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry
Summary
Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks.
Severity
CWE
- CWE-459 - Incomplete Cleanup
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.1.0
(semver)
Unaffected: 6.1.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "deedim"
},
{
"lang": "en",
"type": "finder",
"value": "jvff"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-07-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block\u0027s hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-459",
"description": "Incomplete Cleanup",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:07.777Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8gxx-hc65-vv82)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8gxx-hc65-vv82"
},
{
"name": "VulnCheck Advisory: Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-chain-stall-via-stale-parent-error-map-entry"
}
],
"title": "Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104427",
"datePublished": "2026-10-02T11:38:07.777Z",
"dateReserved": "2026-10-02T00:46:23.831Z",
"dateUpdated": "2026-10-02T11:38:07.777Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104426 (GCVE-0-2026-104426)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check
Summary
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds.
Severity
CWE
- CWE-407 - Inefficient Algorithmic Complexity
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.1.0
(semver)
Unaffected: 6.1.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ValarDragon"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
}
],
"datePublic": "2026-07-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-407",
"description": "Inefficient Algorithmic Complexity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:07.187Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-4g24-549m-hp75)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4g24-549m-hp75"
},
{
"name": "VulnCheck Advisory: Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-quadratic-complexity-dos-via-block-transparent-value-check"
}
],
"title": "Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104426",
"datePublished": "2026-10-02T11:38:07.187Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:07.187Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104425 (GCVE-0-2026-104425)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions
Summary
ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.
Severity
5.3 (Medium)
CWE
- CWE-405 - Asymmetric Resource Consumption (Amplification)
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.1.0
(semver)
Unaffected: 6.1.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ValarDragon"
},
{
"lang": "en",
"type": "reporter",
"value": "ebfull"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-07-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-405",
"description": "Asymmetric Resource Consumption (Amplification)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:06.504Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-g7c4-2w6c-cr3r)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-g7c4-2w6c-cr3r"
},
{
"name": "VulnCheck Advisory: Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-batch-verification-poisoning-dos-via-unattributed-pushed-transactions"
}
],
"title": "Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104425",
"datePublished": "2026-10-02T11:38:06.504Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:06.504Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104424 (GCVE-0-2026-104424)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate
Summary
Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.
Severity
CWE
- CWE-131 - Incorrect Calculation of Buffer Size
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.1.0
(semver)
Unaffected: 6.1.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ebfull"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-07-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner\u0027s mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-131",
"description": "Incorrect Calculation of Buffer Size",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:05.827Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-95m2-vx53-v2jw)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-95m2-vx53-v2jw"
},
{
"name": "VulnCheck Advisory: Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-incorrect-block-size-calculation-in-getblocktemplate"
}
],
"title": "Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104424",
"datePublished": "2026-10-02T11:38:05.827Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:05.827Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104423 (GCVE-0-2026-104423)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification
Summary
Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.
Severity
CWE
- CWE-405 - Asymmetric Resource Consumption (Amplification)
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.2.1
(semver)
Unaffected: 6.2.1 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-08-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.2.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.2.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.2.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "craftsoldier"
},
{
"lang": "en",
"type": "finder",
"value": "conradoplg"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-08-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-405",
"description": "Asymmetric Resource Consumption (Amplification)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:05.140Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-2p4c-3q4q-p463)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2p4c-3q4q-p463"
},
{
"name": "VulnCheck Advisory: Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.2.1-denial-of-service-via-uncapped-v6-shielded-proof-verification"
}
],
"title": "Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104423",
"datePublished": "2026-10-02T11:38:05.140Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:05.140Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104422 (GCVE-0-2026-104422)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite
Summary
The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block.
Severity
CWE
- CWE-345 - Insufficient Verification of Data Authenticity
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.3.0
(semver)
Unaffected: 6.3.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-08-11 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/Zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.3.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-08-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The block sync download path in Zebra (zebrad) before 6.3.0 reads a block\u0027s height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node\u0027s discovery of the newest block."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-345",
"description": "Insufficient Verification of Data Authenticity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:03.646Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-g95h-hw6g-pvgv)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-g95h-hw6g-pvgv"
},
{
"name": "VulnCheck Advisory: Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-block-sync-denial-of-service-via-coinbase-scriptsig-rewrite"
}
],
"title": "Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104422",
"datePublished": "2026-10-02T11:38:03.646Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:03.646Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104421 (GCVE-0-2026-104421)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 12:28
VLAI
EPSS
VEX
Title
Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout
Summary
Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 12:27 UTC
CWE
- CWE-459 - Incomplete Cleanup
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.2.1
(semver)
Unaffected: 6.2.1 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-22 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104421",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T12:27:43.846358Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T12:28:10.585Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.2.1",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.2.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.2.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-07-22T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block\u0027s header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-459",
"description": "Incomplete Cleanup",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:02.456Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-x93j-mj2f-q338)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-x93j-mj2f-q338"
},
{
"name": "VulnCheck Advisory: Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.2.1-block-download-denial-of-service-via-knownblock-senthashes-lockout"
}
],
"title": "Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104421",
"datePublished": "2026-10-02T11:38:02.456Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T12:28:10.585Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104420 (GCVE-0-2026-104420)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks
Summary
Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.
Severity
5.3 (Medium)
CWE
- CWE-704 - Incorrect Type Conversion or Cast
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.3.0
(semver)
Unaffected: 6.3.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-08-11 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.3.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "evan-forbes"
}
],
"datePublic": "2026-08-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-704",
"description": "Incorrect Type Conversion or Cast",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:01.836Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8hh2-hrf2-cqf4)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8hh2-hrf2-cqf4"
},
{
"name": "VulnCheck Advisory: Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-peer-misbehavior-ban-bypass-via-gossiped-blocks"
}
],
"title": "Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104420",
"datePublished": "2026-10-02T11:38:01.836Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:01.836Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104419 (GCVE-0-2026-104419)
Vulnerability from nvd – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes
Summary
Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.
Severity
4.8 (Medium)
CWE
- CWE-345 - Insufficient Verification of Data Authenticity
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.3.0
(semver)
Unaffected: 6.3.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-08-11 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.3.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "zakura-security"
}
],
"datePublic": "2026-08-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-345",
"description": "Insufficient Verification of Data Authenticity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:01.103Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-qhr3-cvch-5fh2)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-qhr3-cvch-5fh2"
},
{
"name": "VulnCheck Advisory: Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-honest-peer-banning-via-far-ahead-findblocks-hashes"
}
],
"title": "Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104419",
"datePublished": "2026-10-02T11:38:01.103Z",
"dateReserved": "2026-10-02T00:44:44.529Z",
"dateUpdated": "2026-10-02T11:38:01.103Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104437 (GCVE-0-2026-104437)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling
Summary
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Severity
CWE
- CWE-347 - Improper Verification of Cryptographic Signature
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 4.4.0
(semver)
Unaffected: 4.4.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-05-02 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.4.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.4.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.4.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sangsoo-osec"
},
{
"lang": "en",
"type": "reporter",
"value": "defuse"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-05-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:13.855Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-cwfq-rfcr-8hmp)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-cwfq-rfcr-8hmp"
},
{
"name": "VulnCheck Advisory: Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-4.4.0-consensus-split-via-sighash-single-missing-output-handling"
}
],
"title": "Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104437",
"datePublished": "2026-10-02T11:38:13.855Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:13.855Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104436 (GCVE-0-2026-104436)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length
Summary
Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.
Severity
CWE
- CWE-770 - Allocation of Resources Without Limits or Throttling
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 4.5.0
(semver)
Unaffected: 4.5.0 (semver) |
|
| ZcashFoundation | zebra |
Affected:
0 , < 8.0.0
(semver)
Unaffected: 8.0.0 (semver) |
Date Public
2026-05-29 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.5.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-chain",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "8.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "dingledropper"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
}
],
"datePublic": "2026-05-29T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 3.7,
"baseSeverity": "LOW",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:13.172Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-443g-gwgp-49x4)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-443g-gwgp-49x4"
},
{
"name": "VulnCheck Advisory: Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-4.5.0-cpu-amplification-via-uncapped-getblocks-getheaders-locator-length"
}
],
"title": "Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104436",
"datePublished": "2026-10-02T11:38:13.172Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:13.172Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104435 (GCVE-0-2026-104435)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output
Summary
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Severity
CWE
- CWE-347 - Improper Verification of Cryptographic Signature
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-4.4.0-… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
4.4.0 , < 4.4.1
(semver)
Unaffected: 4.4.1 (semver) |
|
| ZcashFoundation | zebra |
Affected:
6.0.0 , < 6.0.1
(semver)
Unaffected: 6.0.1 (semver) |
Date Public
2026-05-04 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.4.1",
"status": "affected",
"version": "4.4.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.4.1",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-script",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.0.1",
"status": "affected",
"version": "6.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.0.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.4.1",
"versionStartIncluding": "4.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.1",
"versionStartIncluding": "6.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sangsoo-osec"
},
{
"lang": "en",
"type": "reporter",
"value": "fivelittleducks"
}
],
"datePublic": "2026-05-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-347",
"description": "Improper Verification of Cryptographic Signature",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:12.487Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-pvmv-cwg8-v6c8)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-pvmv-cwg8-v6c8"
},
{
"name": "VulnCheck Advisory: Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-4.4.0-consensus-divergence-via-v5-sighash-single-without-output"
}
],
"title": "Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104435",
"datePublished": "2026-10-02T11:38:12.487Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:12.487Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104434 (GCVE-0-2026-104434)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC
Summary
ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.
Severity
CWE
- CWE-617 - Reachable Assertion
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 8.0.0
(semver)
Unaffected: 8.0.0 (semver) |
|
| ZcashFoundation | zebra |
Affected:
0 , < 4.5.0
(semver)
Unaffected: 4.5.0 (semver) |
Date Public
2026-05-29 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-rpc",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "8.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.5.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "8.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "robustfengbin"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-05-29T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-617",
"description": "Reachable Assertion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:11.845Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-c8w6-x74f-vmg3)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-c8w6-x74f-vmg3"
},
{
"name": "VulnCheck Advisory: Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-8.0.0-denial-of-service-via-z-listunifiedreceivers-rpc"
}
],
"title": "Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104434",
"datePublished": "2026-10-02T11:38:11.845Z",
"dateReserved": "2026-10-02T00:50:26.604Z",
"dateUpdated": "2026-10-02T11:38:11.845Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104432 (GCVE-0-2026-104432)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response
Summary
Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.
Severity
5.3 (Medium)
CWE
- CWE-754 - Improper Check for Unusual or Exceptional Conditions
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.3.0
(semver)
Unaffected: 6.3.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-08-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/Zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.3.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.3.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Maakai123"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
}
],
"datePublic": "2026-08-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-754",
"description": "Improper Check for Unusual or Exceptional Conditions",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:11.214Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-h8m8-844p-v3m9)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-h8m8-844p-v3m9"
},
{
"name": "VulnCheck Advisory: Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-false-readiness-via-discarded-one-hash-findblocks-response"
}
],
"title": "Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104432",
"datePublished": "2026-10-02T11:38:11.214Z",
"dateReserved": "2026-10-02T00:50:26.603Z",
"dateUpdated": "2026-10-02T11:38:11.214Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104431 (GCVE-0-2026-104431)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification
Summary
Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.
Severity
CWE
- CWE-405 - Asymmetric Resource Consumption (Amplification)
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.0.0
(semver)
Unaffected: 6.0.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-13 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ouicate"
},
{
"lang": "en",
"type": "finder",
"value": "conradoplg"
}
],
"datePublic": "2026-07-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-405",
"description": "Asymmetric Resource Consumption (Amplification)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:10.560Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-84j3-rw4c-gqmj)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-84j3-rw4c-gqmj"
},
{
"name": "VulnCheck Advisory: Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.0.0-denial-of-service-via-synchronous-script-ffi-verification"
}
],
"title": "Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104431",
"datePublished": "2026-10-02T11:38:10.560Z",
"dateReserved": "2026-10-02T00:50:26.603Z",
"dateUpdated": "2026-10-02T11:38:10.560Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104430 (GCVE-0-2026-104430)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount
Summary
Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.
Severity
CWE
- CWE-628 - Function Call with Incorrectly Specified Arguments
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-4.5.0-… | third-party-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
4.5.0 , < 4.5.1
(semver)
Unaffected: 4.5.1 (semver) |
|
| ZcashFoundation | zebra |
Affected:
7.0.0 , < 7.0.1
(semver)
Unaffected: 7.0.1 (semver) |
Date Public
2026-06-01 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "4.5.1",
"status": "affected",
"version": "4.5.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "4.5.1",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-script",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "7.0.1",
"status": "affected",
"version": "7.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.0.1",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "4.5.1",
"versionStartIncluding": "4.5.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0.1",
"versionStartIncluding": "7.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "sangsoo-osec"
}
],
"datePublic": "2026-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd\u0027s accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra\u0027s inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-628",
"description": "Function Call with Incorrectly Specified Arguments",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:09.916Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-2prc-cj5x-4443)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2prc-cj5x-4443"
},
{
"name": "VulnCheck Advisory: Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-4.5.0-consensus-split-via-p2sh-sigop-overcount"
}
],
"title": "Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104430",
"datePublished": "2026-10-02T11:38:09.916Z",
"dateReserved": "2026-10-02T00:50:26.603Z",
"dateUpdated": "2026-10-02T11:38:09.916Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104429 (GCVE-0-2026-104429)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 12:27
VLAI
EPSS
VEX
Title
Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages
Summary
Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-02 12:27 UTC
CWE
- CWE-770 - Allocation of Resources Without Limits or Throttling
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.0.0-rc.0
(semver)
Unaffected: 6.0.0-rc.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-03 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-104429",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T12:27:13.306414Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T12:27:23.589Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.0.0-rc.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.0.0-rc.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.0.0-rc.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "SuplabsYi"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
},
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
}
],
"datePublic": "2026-07-03T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers\u0027 transaction relay."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-770",
"description": "Allocation of Resources Without Limits or Throttling",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:09.257Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-m9xx-8rcj-vmgp)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-m9xx-8rcj-vmgp"
},
{
"name": "VulnCheck Advisory: Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.0.0-rc.0-per-peer-mempool-admission-bypass-via-p2p-tx-messages"
}
],
"title": "Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104429",
"datePublished": "2026-10-02T11:38:09.257Z",
"dateReserved": "2026-10-02T00:46:23.831Z",
"dateUpdated": "2026-10-02T12:27:23.589Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104428 (GCVE-0-2026-104428)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 11.0.0 Denial of Service via getblock Verbosity 2
Summary
The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.
Severity
5.3 (Medium)
CWE
- CWE-617 - Reachable Assertion
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 11.0.0
(semver)
Unaffected: 11.0.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-03 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebra-rpc",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "11.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "11.0.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "11.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "coordinator",
"value": "mpguerra"
},
{
"lang": "en",
"type": "reporter",
"value": "defuse"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-07-03T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation\u0027s Zebra node, panics on verbosity 2 for a side-chain block because the block\u0027s -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-617",
"description": "Reachable Assertion",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:08.558Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-x6v8-c2xp-928m)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-x6v8-c2xp-928m"
},
{
"name": "VulnCheck Advisory: Zebra before 11.0.0 Denial of Service via getblock Verbosity 2",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-11.0.0-denial-of-service-via-getblock-verbosity-2"
}
],
"title": "Zebra before 11.0.0 Denial of Service via getblock Verbosity 2",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104428",
"datePublished": "2026-10-02T11:38:08.558Z",
"dateReserved": "2026-10-02T00:46:23.831Z",
"dateUpdated": "2026-10-02T11:38:08.558Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104427 (GCVE-0-2026-104427)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry
Summary
Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks.
Severity
CWE
- CWE-459 - Incomplete Cleanup
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.1.0
(semver)
Unaffected: 6.1.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "deedim"
},
{
"lang": "en",
"type": "finder",
"value": "jvff"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-07-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block\u0027s hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-459",
"description": "Incomplete Cleanup",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:07.777Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-8gxx-hc65-vv82)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8gxx-hc65-vv82"
},
{
"name": "VulnCheck Advisory: Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-chain-stall-via-stale-parent-error-map-entry"
}
],
"title": "Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104427",
"datePublished": "2026-10-02T11:38:07.777Z",
"dateReserved": "2026-10-02T00:46:23.831Z",
"dateUpdated": "2026-10-02T11:38:07.777Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104426 (GCVE-0-2026-104426)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check
Summary
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds.
Severity
CWE
- CWE-407 - Inefficient Algorithmic Complexity
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.1.0
(semver)
Unaffected: 6.1.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ValarDragon"
},
{
"lang": "en",
"type": "finder",
"value": "oxarbitrage"
}
],
"datePublic": "2026-07-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "HIGH",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-407",
"description": "Inefficient Algorithmic Complexity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:07.187Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-4g24-549m-hp75)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4g24-549m-hp75"
},
{
"name": "VulnCheck Advisory: Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-quadratic-complexity-dos-via-block-transparent-value-check"
}
],
"title": "Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104426",
"datePublished": "2026-10-02T11:38:07.187Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:07.187Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-104425 (GCVE-0-2026-104425)
Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
VLAI
EPSS
VEX
Title
Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions
Summary
ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.
Severity
5.3 (Medium)
CWE
- CWE-405 - Asymmetric Resource Consumption (Amplification)
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/ZcashFoundation/zebra/security… | vendor-advisory |
| https://www.vulncheck.com/advisories/zebra-before… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZcashFoundation | zebra |
Affected:
0 , < 6.1.0
(semver)
Unaffected: 6.1.0 (semver) cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* |
Date Public
2026-07-17 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:cargo/zebrad",
"product": "zebra",
"vendor": "ZcashFoundation",
"versions": [
{
"lessThan": "6.1.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ValarDragon"
},
{
"lang": "en",
"type": "reporter",
"value": "ebfull"
},
{
"lang": "en",
"type": "finder",
"value": "upbqdn"
}
],
"datePublic": "2026-07-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-405",
"description": "Asymmetric Resource Consumption (Amplification)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-02T11:38:06.504Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-g7c4-2w6c-cr3r)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-g7c4-2w6c-cr3r"
},
{
"name": "VulnCheck Advisory: Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-batch-verification-poisoning-dos-via-unattributed-pushed-transactions"
}
],
"title": "Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-104425",
"datePublished": "2026-10-02T11:38:06.504Z",
"dateReserved": "2026-10-02T00:46:23.830Z",
"dateUpdated": "2026-10-02T11:38:06.504Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}