Description
Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Bypass of anti‑misbehavior banning mechanism
Action: Immediate Patch
AI Analysis

Impact

Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step incorrectly downcasts RouterError to VerifyBlockError and discards the penalty, so attackers can repeatedly force block download and Equihash verification without ever being banned. This flaw stems from improper type handling, classified as CWE‑704, which leads to incorrect error processing and undermines the network’s anti‑DoS safeguards.

Affected Systems

All Zebra nodes running any release prior to 6.3.0, including the 6.2.x series, remain vulnerable. The data set does not list specific affected versions, so any pre‑6.3.0 node is considered at risk. Nodes that accept gossip from remote peers are susceptible to repeated invalid block submissions by unauthenticated attackers.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a network connection to a target node and the ability to send crafted invalid blocks. No elevated privileges are needed, and the flaw resides in a routine error‑handling path. Attackers could use this to keep malicious peers connected and repeatedly trigger resource‑intensive block validation, thereby causing network churn and potential denial‑of‑service impact to legitimate participants.

Generated by OpenCVE AI on October 2, 2026 at 13:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.3.0 or later to apply the official patch that correctly handles RouterError.
  • Configure the node’s misbehavior score thresholds so that peers receiving a defined number of invalid blocks are banned; adjust settings to reject peers that consistently deliver malformed blocks.
  • Monitor node logs for frequent RouterError events and ensure that VerifyBlockError handling matches the updated logic; retain logs for forensic analysis.

Generated by OpenCVE AI on October 2, 2026 at 13:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.
Title Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-704
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:01.836Z

Reserved: 2026-10-02T00:46:23.830Z

Link: CVE-2026-104420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:11.997

Modified: 2026-10-02T12:17:11.997

Link: CVE-2026-104420

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:45:17Z

Weaknesses
  • CWE-704

    Incorrect Type Conversion or Cast