Impact
Zebra 5.0.0 through every release before 6.0.0-rc.0 fails to enforce the per‑peer mempool admission cap on transactions that arrive as direct P2P tx messages. This omission allows a remote inbound peer to inject a large volume of unique transactions, filling up the mempool slots that would normally be reserved for other peers. The result is a denial of transaction relay for legitimate nodes, which can degrade network throughput and affect transaction confirmations. The flaw falls under CWE‑770, a resource exhaustion weakness.
Affected Systems
The vulnerability is confined to the ZcashFoundation Zebra (zebrad) software. Any instance running a Zebra version starting at 5.0.0 up to, but not including, 6.0.0‑rc.0 is susceptible. The product is the core node implementation that processes peer‑to‑peer transaction messages.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. EPSS is not supplied and the issue is not catalogued in the CISA KEV list. Although no exploit has yet been observed, the bug can be exercised by any remote peer that the node accepts. The attack vector is inferred to be a remote inbound P2P connection sending crafted tx messages, which does not require authentication and therefore offers a high likelihood of exploitation if the node is reachable. The impact is limited to network availability and transaction propagation, but it can propagate enough to affect user trust and overall network health.
OpenCVE Enrichment