CVE-2026-104421

Summary

Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.

Affected Software

VendorProductVersion RangeStatus
ZcashFoundationzebra0 < 6.2.1affected
ZcashFoundationzebra6.2.1unaffected

Weaknesses

  • CWE-459: Incomplete Cleanup

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References