Impact
The vulnerability resides in the getblock RPC method in Zebra versions prior to 11.0.0. When a side‑chain block is queried with verbosity level 2, the node attempts to convert the block's −1 confirmations sentinel into an unsigned 32‑bit integer using .expect(). The resulting panic aborts the entire process. An unauthenticated caller can invoke this RPC repeatedly, causing the node to crash repeatedly and remain in a crash loop. This yields a denial‑of‑service condition that affects availability of the node and, by extension, the network service it provides. The weakness corresponds to CWE‑617, which involves improper handling of user-supplied input or state.
Affected Systems
This affects all Zebra nodes deployed as part of the Zcash Foundation’s infrastructure or by independent operators running Zebra version 1.x.x through 10.x.x. Versions 11.0.0 and later have this logic corrected and are immune to the crash.
Risk and Exploitability
The CVSS score of 6.9 places this vulnerability in the medium severity range, reflecting the impact of an unprivileged remote attacker causing a denial‑of‑service. Because the RPC endpoint is unauthenticated, any attacker who can reach the node over the network can exploit the flaw. EPSS information is not available, so the exact probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, but the attack vector and denial‑of‑service nature make it a concern for operators running public nodes. The recommended mitigation is to apply the vendor’s patch immediately; if an upgrade is delayed, the node should be isolated from the public network or the RPC interface should be locked down.
OpenCVE Enrichment