Impact
Zebra before 4.5.0 has an uncontrolled resource consumption flaw that lets remote peers send getblocks or getheaders messages with oversized block locator vectors. The software performs a chain lookup for each locator hash, which can consume a large number of blocking‑pool threads. The result is a CPU and thread exhaustion that degrades block validation, RPC and mempool performance, effectively causing a denial of service.
Affected Systems
The vulnerability affects the ZcashFoundation Zebra client prior to version 4.5.0. All installations of Zebra before 4.5.0 that allow incoming P2P traffic are vulnerable. The affected product is ZcashFoundation Zebra.
Risk and Exploitability
Exploit requires only the ability to communicate with a Zebra node over the P2P network; authentication is not required. A malicious peer can send a getblocks or getheaders request containing up to 65,535 locator hashes, triggering the per‑hash lookups that exhaust the blocking‑pool threads. The EPSS score is not available, but the CVSS score of 6.3 indicates a moderate severity. The vulnerability is not listed in CISA’s KEV catalog, yet nodes that receive traffic from untrusted peers remain at risk.
OpenCVE Enrichment