Description
ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.
Published: 2026-10-02
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

This vulnerability arises from a reachable assertion in the z_listunifiedreceivers RPC handler of ZcashFoundation Zebra, which triggers a call to expect() on Sapling receiver parsing. When a Unified Address contains an invalid Jubjub point, the assertion fails, causing the zebrad process to abort. The impact is a denial of service, keeping the node offline until an administrator restarts it. The weakness is a classic assertion failure, identified as CWE-617.

Affected Systems

Versions of Zebra before 8.0.0 and zebrad before 4.5.0 are affected. The vulnerability is exploitable through the z_listunifiedreceivers RPC endpoint, which is only accessible to authenticated RPC clients connecting to the node.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity impact for availability. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation. However, the required condition of an authenticated RPC client makes the attack vector rather limited to those controlling a node. Once an attacker has access, they can repeatedly send malicious Unified Addresses to crash the node, leading to sustained downtime.

Generated by OpenCVE AI on October 2, 2026 at 12:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zebra update to version 8.0.0 or later and zebrad update to 4.5.0 or later.
  • Restrict access to the RPC interface, enforcing authentication and limiting connections to trusted IP addresses.
  • Monitor zebrad logs for abnormal shutdowns and verify that the process resumes normally after updates.

Generated by OpenCVE AI on October 2, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.
Title Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-617
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:11.845Z

Reserved: 2026-10-02T00:50:26.604Z

Link: CVE-2026-104434

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:13.917

Modified: 2026-10-02T12:17:13.917

Link: CVE-2026-104434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:05Z

Weaknesses