Description
ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated node to push transactions containing invalid Orchard proofs into the shared halo2 batch verifier, causing the node to divert honest block proofs onto a slower individual verification path. This resource exhaustion leads to roughly a sevenfold slowdown in block processing. The weakness is a type of resource exhaustion, identified as CWE-405.

Affected Systems

ZcashFoundation Zebra is affected, with all releases prior to version 6.1.0 vulnerable. No specific sub-version details are supplied beyond the general "before 6.1.0" qualification.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated peer over the network, able to submit crafted transactions. Exploitability requires no special privileges and can be performed by any external peer that can connect to the node, making it a potentially high‑risk threat in environments where trusted peers are not strictly controlled.

Generated by OpenCVE AI on October 2, 2026 at 13:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.1.0 or later
  • Configure network access controls to restrict connections to trusted peers, such as firewall rules or peer whitelisting
  • Monitor node performance and resource usage for abnormal slowdowns, and block or isolate malicious peers if the DoS is observed

Generated by OpenCVE AI on October 2, 2026 at 13:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.
Title Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-405
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:06.504Z

Reserved: 2026-10-02T00:46:23.830Z

Link: CVE-2026-104425

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:12.730

Modified: 2026-10-02T12:17:12.730

Link: CVE-2026-104425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:45:17Z

Weaknesses
  • CWE-405

    Asymmetric Resource Consumption (Amplification)