CVE-2026-104434 PUBLISHED

Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor ZcashFoundation
Product zebra
Versions Default: unaffected
  • affected from 0 to 8.0.0 (excl.)
  • Version 8.0.0 is unaffected
Vendor ZcashFoundation
Product zebra
Versions Default: unaffected
  • affected from 0 to 4.5.0 (excl.)
  • Version 4.5.0 is unaffected

Credits

  • robustfengbin reporter
  • mpguerra coordinator
  • upbqdn finder

References

Problem Types

  • Reachable Assertion CWE