Impact
Zebra before version 6.3.0 mishandles exception checks within ChainSync::obtain_tips, discarding legitimate one‑hash FindBlocks responses. When a peer returns only the next block hash, the resulting sync sample has zero length, causing the /ready endpoint to report a 200 OK response while the node is actually behind the network tip. This flaw does not expose remote code execution or data leakage but misleads operators into believing the node is fully synchronized, which can compromise transaction validation and network reliability.
Affected Systems
Any Zebra node deployed by Zcash Foundation that has a version older than 6.3.0 is susceptible. The issue resides specifically in the ChainSync component of those releases.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is of moderate severity. The EPSS score is unavailable and the flaw is not listed in CISA’s KEV catalog, suggesting that public exploitation is not widespread. A malicious or misbehaving peer can trigger the problem by returning only the single next block hash; however, the exploit requires participation in normal peer communication and does not provide additional privileges beyond causing incorrect status reporting. Operators should consider the risk of running unsynced nodes while believing they are in sync, especially in environments where the /ready endpoint informs critical processes.
OpenCVE Enrichment