Description
Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.
Published: 2026-10-02
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Moderate resource exhaustion / Denial of Service
Action: Upgrade
AI Analysis

Impact

Zebra before 4.5.0 has an uncontrolled resource consumption flaw that lets remote peers send getblocks or getheaders messages with oversized block locator vectors. The software performs a chain lookup for each locator hash, which can consume a large number of blocking‑pool threads. The result is a CPU and thread exhaustion that degrades block validation, RPC and mempool performance, effectively causing a denial of service.

Affected Systems

The vulnerability affects the ZcashFoundation Zebra client prior to version 4.5.0. All installations of Zebra before 4.5.0 that allow incoming P2P traffic are vulnerable. The affected product is ZcashFoundation Zebra.

Risk and Exploitability

Exploit requires only the ability to communicate with a Zebra node over the P2P network; authentication is not required. A malicious peer can send a getblocks or getheaders request containing up to 65,535 locator hashes, triggering the per‑hash lookups that exhaust the blocking‑pool threads. The EPSS score is not available, but the CVSS score of 6.3 indicates a moderate severity. The vulnerability is not listed in CISA’s KEV catalog, yet nodes that receive traffic from untrusted peers remain at risk.

Generated by OpenCVE AI on October 2, 2026 at 12:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to version 4.5.0 or later, which limits the size of block locator vectors and protects the blocking‑pool threads.
  • If an upgrade is not immediately possible, configure network or node‑level rate limiting to restrict the number of locator hashes accepted from any single peer, or drop messages that exceed a safe threshold.
  • Apply firewall or peer‑filtering rules to block or reduce traffic from unknown or untrusted peers, limiting the exposure to malformed getblocks/getheaders requests.
  • Continuously monitor node CPU usage and thread pool saturation to detect and respond to abnormal behavior.

Generated by OpenCVE AI on October 2, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.
Title Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-770
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T14:51:28.130Z

Reserved: 2026-10-02T00:50:26.604Z

Link: CVE-2026-104436

cve-icon Vulnrichment

Updated: 2026-10-02T14:51:25.345Z

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:14.210

Modified: 2026-10-02T15:17:06.770

Link: CVE-2026-104436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling