CVE-2026-104428 PUBLISHED

Zebra before 11.0.0 Denial of Service via getblock Verbosity 2

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor ZcashFoundation
Product zebra
Versions Default: unaffected
  • affected from 0 to 11.0.0 (excl.)
  • Version 11.0.0 is unaffected

Credits

  • mpguerra coordinator
  • defuse reporter
  • oxarbitrage finder
  • upbqdn finder

References

Problem Types

  • Reachable Assertion CWE