Impact
Zebra nodes prior to version 6.2.1 have an incomplete cleanup bug that lets any unauthenticated peer block block dissemination. An attacker can upload a contextually invalid block that carries the header hash of a valid block. The node then treats that honest block as known and skips its download, while the rejected hash remains recorded in SentHashes. The result is the node staying behind the network tip and unable to fetch new blocks, effectively desynchronizing it from the main chain. This vulnerability is classified as CWE‑459.
Affected Systems
All Zebra client releases from Zcash Foundation dated before 6.2.1 are affected. Any deployment that accepts peer connections without restriction can be impacted because the flaw is triggered by processing incoming block data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, but the absence of an EPSS score and no listing in the CISA KEV catalog suggest limited current exploitation activity. The vulnerability is exploitable over an unauthenticated network, meaning an attacker only needs to be able to send messages to a node's listening port. Successful exploitation leads to a denial of service for that node, preventing it from participating in consensus and potentially causing lagged or stale ledger states. Given the moderate CVSS and potential network impact, organizations should prioritize remediation.
OpenCVE Enrichment