CVE-2026-104431

Summary

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.

Affected Software

VendorProductVersion RangeStatus
ZcashFoundationzebra0 < 6.0.0affected
ZcashFoundationzebra6.0.0unaffected

Weaknesses

  • CWE-405: Asymmetric Resource Consumption (Amplification)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References