Description
Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.
Published: 2026-10-02
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Mempool Denial of Service due to transaction relay starvation
Action: Patch
AI Analysis

Impact

Zebra 5.0.0 through every release before 6.0.0-rc.0 fails to enforce the per‑peer mempool admission cap on transactions that arrive as direct P2P tx messages. This omission allows a remote inbound peer to inject a large volume of unique transactions, filling up the mempool slots that would normally be reserved for other peers. The result is a denial of transaction relay for legitimate nodes, which can degrade network throughput and affect transaction confirmations. The flaw falls under CWE‑770, a resource exhaustion weakness.

Affected Systems

The vulnerability is confined to the ZcashFoundation Zebra (zebrad) software. Any instance running a Zebra version starting at 5.0.0 up to, but not including, 6.0.0‑rc.0 is susceptible. The product is the core node implementation that processes peer‑to‑peer transaction messages.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity. EPSS is not supplied and the issue is not catalogued in the CISA KEV list. Although no exploit has yet been observed, the bug can be exercised by any remote peer that the node accepts. The attack vector is inferred to be a remote inbound P2P connection sending crafted tx messages, which does not require authentication and therefore offers a high likelihood of exploitation if the node is reachable. The impact is limited to network availability and transaction propagation, but it can propagate enough to affect user trust and overall network health.

Generated by OpenCVE AI on October 2, 2026 at 12:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.0.0‑rc.0 or later where the per‑peer admission cap is applied to P2P tx messages.
  • Restrict inbound peer connections to known, trusted nodes via firewall or peers.allow configuration to reduce the attack surface.
  • Continuously monitor mempool size and peer transaction rates for abnormal spikes that may indicate abuse of the mempool admission rule.

Generated by OpenCVE AI on October 2, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.
Title Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-770
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T12:27:23.589Z

Reserved: 2026-10-02T00:46:23.831Z

Link: CVE-2026-104429

cve-icon Vulnrichment

Updated: 2026-10-02T12:27:19.705Z

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:13.323

Modified: 2026-10-02T13:17:43.500

Link: CVE-2026-104429

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling