Description
Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via block download lockout
Action: Apply Patch
AI Analysis

Impact

Zebra nodes prior to version 6.2.1 have an incomplete cleanup bug that lets any unauthenticated peer block block dissemination. An attacker can upload a contextually invalid block that carries the header hash of a valid block. The node then treats that honest block as known and skips its download, while the rejected hash remains recorded in SentHashes. The result is the node staying behind the network tip and unable to fetch new blocks, effectively desynchronizing it from the main chain. This vulnerability is classified as CWE‑459.

Affected Systems

All Zebra client releases from Zcash Foundation dated before 6.2.1 are affected. Any deployment that accepts peer connections without restriction can be impacted because the flaw is triggered by processing incoming block data.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, but the absence of an EPSS score and no listing in the CISA KEV catalog suggest limited current exploitation activity. The vulnerability is exploitable over an unauthenticated network, meaning an attacker only needs to be able to send messages to a node's listening port. Successful exploitation leads to a denial of service for that node, preventing it from participating in consensus and potentially causing lagged or stale ledger states. Given the moderate CVSS and potential network impact, organizations should prioritize remediation.

Generated by OpenCVE AI on October 2, 2026 at 12:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.2.1 or later to remove the cleanup flaw
  • Limit or filter incoming peer connections to trusted nodes to reduce exposure to crafted block messages
  • Restart the node after applying the update to ensure the SentHashes cache is cleared

Generated by OpenCVE AI on October 2, 2026 at 12:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.
Title Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-459
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T12:28:10.585Z

Reserved: 2026-10-02T00:46:23.830Z

Link: CVE-2026-104421

cve-icon Vulnrichment

Updated: 2026-10-02T12:27:58.279Z

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:12.143

Modified: 2026-10-02T13:17:42.550

Link: CVE-2026-104421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T12:30:20Z

Weaknesses