CVE-2026-104419

Summary

Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.

Affected Software

VendorProductVersion RangeStatus
ZcashFoundationzebra0 < 6.3.0affected
ZcashFoundationzebra6.3.0unaffected

Weaknesses

  • CWE-345: Insufficient Verification of Data Authenticity

References