Description
Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.
Published: 2026-10-02
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via Peer Banning
Action: Apply Patch
AI Analysis

Impact

Zebra nodes from version 4.5.0 up to, but not including, 6.3.0 ignore which peer supplied block hashes in FindBlocks responses. When a peer provides hashes for blocks more than fifty thousand heights above the node's tip, the node assigns the maximum 100 misbehavior points—the ban threshold—to that peer without verifying origin. This causes honest peers to be unjustly penalized and disconnected, weakening the node's peer network and escalating the risk of eclipse attacks. The flaw corresponds to CWE‑345, indicating an improper handling of peer reputation misclassification.

Affected Systems

All Zcash Foundation Zebra nodes running any release from version 4.5.0 through any version prior to 6.3.0 are affected, as these versions contain the flawed calculation of misbehavior points when handling far‑ahead FindBlocks replies.

Risk and Exploitability

The CVSS score of 6.3 classifies this vulnerability as moderate severity. No EPSS score is available, so the likelihood of exploitation is unknown, but the attack requires only the ability to act as a network peer; no client‑side credentials or elevated privileges are necessary. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation reports.

Generated by OpenCVE AI on October 2, 2026 at 13:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.3.0 or newer to eliminate the bug that applies misbehavior points for far‑ahead FindBlocks replies.
  • If an immediate upgrade is not possible, restrict inbound connections to pre‑verified peers or apply firewall rules that block untrusted nodes, reducing the chance that a malicious peer can supply far‑ahead hashes to the node.
  • Continuously monitor the node’s misbehavior score logs and be prepared to manually disconnect peers that approach the ban threshold to maintain a healthy peer set.

Generated by OpenCVE AI on October 2, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.
Title Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-345
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:01.103Z

Reserved: 2026-10-02T00:44:44.529Z

Link: CVE-2026-104419

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:11.850

Modified: 2026-10-02T17:59:09.430

Link: CVE-2026-104419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:45:18Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity