CVE-2026-104423
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZcashFoundation | zebra | 0 < 6.2.1 | affected |
| ZcashFoundation | zebra | 6.2.1 | unaffected |
Weaknesses
- CWE-405: Asymmetric Resource Consumption (Amplification)
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2p4c-3q4q-p463
- https://www.vulncheck.com/advisories/zebra-before-6.2.1-denial-of-service-via-uncapped-v6-shielded-proof-verification
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.