Description
Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.
Published: 2026-10-02
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via oversized block templates
Action: Patch
AI Analysis

Impact

Zebra before 6.1.0 contains an incorrect calculation in its block template selector that omits header and transaction-count size from the block budget. This flaw allows an attacker to create transactions that, when added to a miner's mempool, cause the block size calculation to exceed the network limit, leading to rejected blocks and wasted computational effort. The weakness is a numeric overflow miscalculation (CWE-131).

Affected Systems

The vulnerability affects Zcash Foundation's Zebra nodes with any version prior to 6.1.0. These nodes are used by mining operators and full-node validators in the Zcash network.

Risk and Exploitability

The CVSS score of 6.3 indicates medium severity. EPSS data is not available, and the flaw is not listed in CISA's KEV catalog, suggesting a lower current exploitation probability. The description indicates that an attacker must be able to place transactions into the miner's mempool, although the exact method of access is not specified in the advisory. Successful exploitation causes block rejection and wasted proof-of-work, potentially reducing a miner's revenue.

Generated by OpenCVE AI on October 2, 2026 at 13:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.1.0 or later where the block size calculation bug is fixed.
  • Configure the node to enforce strict block size limits when assembling blocks from the mempool, rejecting any candidate that would exceed the network size limit.
  • Review and restrict external interfaces that allow transaction submission to the node, ensuring only trusted clients can send potentially oversized transaction sets.

Generated by OpenCVE AI on October 2, 2026 at 13:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.
Title Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-131
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:05.827Z

Reserved: 2026-10-02T00:46:23.830Z

Link: CVE-2026-104424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T12:17:12.580

Modified: 2026-10-02T17:59:09.430

Link: CVE-2026-104424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:45:18Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size