CVE-2026-104420
Received Received - Intake

Zebra Protection Mechanism Failure Before 6.3.0

Vulnerability report for CVE-2026-104420, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zebra zebra to 6.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-704 The product does not correctly convert an object, resource, or structure from one type to a different type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104420 is a vulnerability in Zebra node software versions 2.3.0 through 6.2.3. It allows unauthenticated peers to send invalid gossiped blocks without being banned. The issue occurs because the system incorrectly handles misbehavior scores during error downcasting, discarding penalties for malicious peers.

Detection Guidance

Monitor Zebra node logs for repeated invalid gossiped block attempts from peers. Check for peers sending consensus-invalid blocks without being banned. Use network monitoring tools to detect unusual bandwidth or CPU usage from specific peers.

Impact Analysis

This vulnerability can cause increased resource consumption on affected systems. Attackers may repeatedly force block downloads and verification processes, consuming bandwidth and CPU without being blocked. This could degrade performance or disrupt normal operation of Zebra nodes.

Compliance Impact

This vulnerability primarily impacts resource consumption and peer management in Zebra nodes, which may indirectly affect compliance with standards like GDPR or HIPAA by increasing the risk of service disruption or unauthorized resource usage. However, the vulnerability does not directly lead to data breaches or unauthorized access to sensitive information.

Mitigation Strategies

Upgrade Zebra to version 6.3.0 or later to patch the vulnerability. If upgrading is not immediately possible, consider temporarily restricting peer connections or monitoring resource usage closely.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104420. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart