CVE-2026-104436 PUBLISHED

Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor ZcashFoundation
Product zebra
Versions Default: unaffected
  • affected from 0 to 4.5.0 (excl.)
  • Version 4.5.0 is unaffected
Vendor ZcashFoundation
Product zebra
Versions Default: unaffected
  • affected from 0 to 8.0.0 (excl.)
  • Version 8.0.0 is unaffected

Credits

  • dingledropper reporter
  • mpguerra coordinator
  • oxarbitrage finder

References

Problem Types

  • Allocation of Resources Without Limits or Throttling CWE