Description
Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks.
Published: 2026-10-02
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Denial of Service – node synchronization stall
Action: Immediate Patch
AI Analysis

Impact

Zebra before 6.1.0 contains an incomplete cleanup in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning the parent_error_map. An attacker can send a coinbase‑malleated block that shares a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks. This results in a denial of service that prevents the node from advancing in the chain and disrupts consensus participation.

Affected Systems

The vulnerability affects ZcashFoundation’s Zebra node software prior to version 6.1.0. Users running any Zebra release before 6.1.0 are impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity. The EPSS score is not available, so the likelihood of exploitation is unknown, but the vulnerability can be exploited over the network by any untrusted peer that can send malformed blocks. The vulnerability is not listed in CISA’s KEV catalog and requires no credentials, making it a potential threat to any publicly reachable node.

Generated by OpenCVE AI on October 2, 2026 at 12:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.1.0 or later from the ZcashFoundation repository.
  • Reboot the node after the upgrade to clear any stale state entries and ensure the new code is active.
  • Configure the node to accept connections only from trusted peers or employ a revocation list to reduce exposure to malicious block injections.

Generated by OpenCVE AI on October 2, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks.
Title Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-459
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:07.777Z

Reserved: 2026-10-02T00:46:23.831Z

Link: CVE-2026-104427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:13.030

Modified: 2026-10-02T12:17:13.030

Link: CVE-2026-104427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:45:17Z

Weaknesses