CVE-2026-104423 PUBLISHED

Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor ZcashFoundation
Product zebra
Versions Default: unaffected
  • affected from 0 to 6.2.1 (excl.)
  • Version 6.2.1 is unaffected

Credits

  • craftsoldier reporter
  • conradoplg finder
  • upbqdn finder

References

Problem Types

  • Asymmetric Resource Consumption (Amplification) CWE