Impact
Zebra nodes from version 4.5.0 up to, but not including, 6.3.0 ignore which peer supplied block hashes in FindBlocks responses. When a peer provides hashes for blocks more than fifty thousand heights above the node's tip, the node assigns the maximum 100 misbehavior points—the ban threshold—to that peer without verifying origin. This causes honest peers to be unjustly penalized and disconnected, weakening the node's peer network and escalating the risk of eclipse attacks. The flaw corresponds to CWE‑345, indicating an improper handling of peer reputation misclassification.
Affected Systems
All Zcash Foundation Zebra nodes running any release from version 4.5.0 through any version prior to 6.3.0 are affected, as these versions contain the flawed calculation of misbehavior points when handling far‑ahead FindBlocks replies.
Risk and Exploitability
The CVSS score of 6.3 classifies this vulnerability as moderate severity. No EPSS score is available, so the likelihood of exploitation is unknown, but the attack requires only the ability to act as a network peer; no client‑side credentials or elevated privileges are necessary. The vulnerability is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation reports.
OpenCVE Enrichment