Description
Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

Zebra (zebrad) before version 6.2.1 exposes an asymmetric resource consumption flaw (CWE-405) that lets any unauthenticated peer stall block verification by submitting V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared, unprioritized Halo2 verification queue with zero‑fee transactions that contain zero‑filled Orchard and Ironwood proofs. The overload forces full‑node software to lag behind the latest block, effectively denying availability of the node, and there is no indication of data integrity or confidentiality impact.

Affected Systems

All ZcashFoundation Zebra nodes running the zebrad daemon with a release older than 6.2.1 are affected. Deployments of zebra before 6.2.1 that expose the default RPC or P2P ports to the internet are vulnerable to the described attack. Based on the description it is inferred that exposing these ports increases exposure.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity. With no privilege required and no special conditions, an attacker can send crafted transactions from any remote address, making the exploitation probability high. EPSS is not available, and the description does not detail mitigation measures in earlier releases, so risk remains elevated. The vulnerability is not listed in the CISA KEV catalog; there is no data on the prevalence of public nodes, so potential operational impact is uncertain.

Generated by OpenCVE AI on October 2, 2026 at 13:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.2.1 or later to apply the official patch.
  • If an upgrade cannot be performed immediately, limit the zebrad network access to trusted peers only; configure a firewall or VPN to block unauthenticated connections to the P2P ports.
  • Continuously monitor block height and verification latency; if a node falls behind the chain tip, investigate for malicious traffic and consider temporarily shutting down or removing untrusted peers.

Generated by OpenCVE AI on October 2, 2026 at 13:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.
Title Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-405
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T15:55:54.144Z

Reserved: 2026-10-02T00:46:23.830Z

Link: CVE-2026-104423

cve-icon Vulnrichment

Updated: 2026-10-02T15:55:50.759Z

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:12.433

Modified: 2026-10-02T16:16:45.407

Link: CVE-2026-104423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:15:07Z

Weaknesses
  • CWE-405

    Asymmetric Resource Consumption (Amplification)