Impact
This vulnerability arises from a reachable assertion in the z_listunifiedreceivers RPC handler of ZcashFoundation Zebra, which triggers a call to expect() on Sapling receiver parsing. When a Unified Address contains an invalid Jubjub point, the assertion fails, causing the zebrad process to abort. The impact is a denial of service, keeping the node offline until an administrator restarts it. The weakness is a classic assertion failure, identified as CWE-617.
Affected Systems
Versions of Zebra before 8.0.0 and zebrad before 4.5.0 are affected. The vulnerability is exploitable through the z_listunifiedreceivers RPC endpoint, which is only accessible to authenticated RPC clients connecting to the node.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact for availability. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation. However, the required condition of an authenticated RPC client makes the attack vector rather limited to those controlling a node. Once an attacker has access, they can repeatedly send malicious Unified Addresses to crash the node, leading to sustained downtime.
OpenCVE Enrichment