Impact
Zebra before 6.0.0 contains a denial‑of‑service flaw that allows unauthenticated peers to stall Tokio workers by submitting expensive synchronous script verification transactions. Non‑standard high‑sigop P2SH transactions reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.
Affected Systems
Affected vendor and product: ZcashFoundation Zebra. Versions before 6.0.0 are vulnerable. Any deployment of these versions that is reachable by unauthenticated peers is at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. EPSS is not available, so the precise likelihood of exploitation is unknown, but attack vectors exist over the network as the flaw is triggered by unauthenticated traffic. Attackers do not require local privileges; they can send custom mempool transactions to the node via TCP, forcing the verifier buffer to fill and causing a denial of service. The vulnerability is not listed in CISA’s KEV catalog, but the high score suggests significant impact if exploited.
OpenCVE Enrichment