CVE-2026-104419
Received Received - Intake

Zebra Peer Misbehavior Points Erosion in zcashd

Vulnerability report for CVE-2026-104419, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zebra zebrad to 6.3.0 (exc)
zebra zebrad From 4.5.0 (inc) to 6.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zebra versions 4.5.0 to 6.2.3 have a flaw where the software does not track which peer provides block hashes in FindBlocks responses. When a syncing node requests a block far ahead of the network tip, Zebra assigns 100 misbehavior pointsβ€”the ban thresholdβ€”to the peer serving the block. Attackers can exploit this by returning real but far-ahead hashes, causing honest peers to be banned. This reduces the victim's peer set and increases eclipse attack risk.

Detection Guidance

Monitor Zebra logs for repeated banning of peers with misbehavior points. Check for peers banned after serving blocks more than 50,000 heights ahead of the tip. Use network monitoring tools to detect unusual peer set reductions or eclipse attack patterns.

Impact Analysis

This vulnerability can disrupt node synchronization by banning honest peers, leading to sync failures or delays. It increases the risk of an eclipse attack, where an attacker gains control over a significant portion of the network's connections. Operators syncing after a long outage are most vulnerable.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to peer-to-peer network operations in blockchain software rather than data protection or privacy controls.

Mitigation Strategies

Upgrade Zebra to version 6.3.0 or later to patch the vulnerability. If unable to upgrade immediately, restrict inbound peer connections and monitor peer bans closely. Avoid syncing from a long outage to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104419. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart