Impact
Zebra before 6.1.0 contains an incomplete cleanup in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning the parent_error_map. An attacker can send a coinbase‑malleated block that shares a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks. This results in a denial of service that prevents the node from advancing in the chain and disrupts consensus participation.
Affected Systems
The vulnerability affects ZcashFoundation’s Zebra node software prior to version 6.1.0. Users running any Zebra release before 6.1.0 are impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is not available, so the likelihood of exploitation is unknown, but the vulnerability can be exploited over the network by any untrusted peer that can send malformed blocks. The vulnerability is not listed in CISA’s KEV catalog and requires no credentials, making it a potential threat to any publicly reachable node.
OpenCVE Enrichment