Impact
The vulnerability allows an unauthenticated node to push transactions containing invalid Orchard proofs into the shared halo2 batch verifier, causing the node to divert honest block proofs onto a slower individual verification path. This resource exhaustion leads to roughly a sevenfold slowdown in block processing. The weakness is a type of resource exhaustion, identified as CWE-405.
Affected Systems
ZcashFoundation Zebra is affected, with all releases prior to version 6.1.0 vulnerable. No specific sub-version details are supplied beyond the general "before 6.1.0" qualification.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated peer over the network, able to submit crafted transactions. Exploitability requires no special privileges and can be performed by any external peer that can connect to the node, making it a potentially high‑risk threat in environments where trusted peers are not strictly controlled.
OpenCVE Enrichment