Impact
Zebra (zebrad) before version 6.2.1 exposes an asymmetric resource consumption flaw (CWE-405) that lets any unauthenticated peer stall block verification by submitting V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared, unprioritized Halo2 verification queue with zero‑fee transactions that contain zero‑filled Orchard and Ironwood proofs. The overload forces full‑node software to lag behind the latest block, effectively denying availability of the node, and there is no indication of data integrity or confidentiality impact.
Affected Systems
All ZcashFoundation Zebra nodes running the zebrad daemon with a release older than 6.2.1 are affected. Deployments of zebra before 6.2.1 that expose the default RPC or P2P ports to the internet are vulnerable to the described attack. Based on the description it is inferred that exposing these ports increases exposure.
Risk and Exploitability
The CVSS score of 8.7 classifies the flaw as high severity. With no privilege required and no special conditions, an attacker can send crafted transactions from any remote address, making the exploitation probability high. EPSS is not available, and the description does not detail mitigation measures in earlier releases, so risk remains elevated. The vulnerability is not listed in the CISA KEV catalog; there is no data on the prevalence of public nodes, so potential operational impact is uncertain.
OpenCVE Enrichment