Description
Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

Zebra before 6.0.0 contains a denial‑of‑service flaw that allows unauthenticated peers to stall Tokio workers by submitting expensive synchronous script verification transactions. Non‑standard high‑sigop P2SH transactions reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.

Affected Systems

Affected vendor and product: ZcashFoundation Zebra. Versions before 6.0.0 are vulnerable. Any deployment of these versions that is reachable by unauthenticated peers is at risk.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. EPSS is not available, so the precise likelihood of exploitation is unknown, but attack vectors exist over the network as the flaw is triggered by unauthenticated traffic. Attackers do not require local privileges; they can send custom mempool transactions to the node via TCP, forcing the verifier buffer to fill and causing a denial of service. The vulnerability is not listed in CISA’s KEV catalog, but the high score suggests significant impact if exploited.

Generated by OpenCVE AI on October 2, 2026 at 12:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 6.0.0 or later
  • If an upgrade is not possible, configure the node to reject or ignore non‑standard high‑sigop P2SH transactions before script verification, such as tightening mempool policy
  • Monitor node performance, set alerts for high CPU or stalled worker counts, and block peers that generate such traffic

Generated by OpenCVE AI on October 2, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.
Title Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-405
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:53:54.651Z

Reserved: 2026-10-02T00:50:26.603Z

Link: CVE-2026-104431

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:13.610

Modified: 2026-10-02T12:17:13.610

Link: CVE-2026-104431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:14Z

Weaknesses
  • CWE-405

    Asymmetric Resource Consumption (Amplification)