CVE-2026-104421
Received Received - Intake

Zebra before 6.2.1 Incomplete Cleanup Flaw

Vulnerability report for CVE-2026-104421, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zebra zebra to 6.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104421 is a vulnerability in Zebra, a Rust implementation of the Zcash node software, affecting versions prior to 6.2.1. The issue involves 'poisoned blocks' that delay the download of valid blocks by exploiting a lockout mechanism in the KnownBlock path. An attacker sends a contextually invalid block with the same header hash as a valid block, causing Zebra to reject it but leave a stale entry in the SentHashes list. This prevents the node from downloading the honest block, keeping it one block behind the network tip.

Detection Guidance

Check Zebra version with 'zebrad --version'. If running version below 6.2.1, the system is vulnerable. Monitor node logs for repeated block rejection events or peers sending blocks with mismatched contexts but same header hashes.

Impact Analysis

This vulnerability allows unauthenticated peers to perform a Denial of Service (DoS) attack by blocking the download of valid blocks. Nodes may become stuck behind the blockchain tip, delaying synchronization with the network. The impact is bounded as the affected state is in memory and clears on restart, but it can persist until the node restarts or unrelated commit activity occurs.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by preventing nodes from downloading valid blocks, which could disrupt blockchain operations. It does not directly impact data privacy or security controls required by GDPR or HIPAA. However, prolonged downtime or service disruption might indirectly affect compliance with availability requirements in these regulations.

Mitigation Strategies

Upgrade Zebra to version 6.2.1 or later. Alternatively, restart the Zebra node to clear the in-memory SentHashes list. Ensure all peers are running patched versions to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104421. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart