CVE-2026-104423
Received Received - Intake

Zebra Blockchain Node Halo2 Proof Verification DoS

Vulnerability report for CVE-2026-104423, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zebra zebrad to 6.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-405 The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104423 is a high-severity asymmetric resource consumption vulnerability in Zebra, a Zcash node software implementation. It allows unauthenticated peers to stall block verification by sending V6 transactions with invalid but properly sized Halo2 proofs. The issue occurs because Zebra counts transactions rather than proof verification costs in its mempool, enabling attackers to flood the verification queue with zero-fee transactions containing multiple expensive proofs like Orchard and Ironwood. This causes nodes to fall behind the chain tip without crashing or causing consensus faults.

Detection Guidance

Monitor Zebra node performance for unusual delays in block processing or increased CPU/memory usage. Check logs for peers sending V6 transactions with invalid Halo2 proofs. Use network monitoring tools to detect sudden spikes in transaction volume from specific peers.

Impact Analysis

This vulnerability primarily causes an availability issue where nodes stall block processing, delaying honest transactions and preventing the node from keeping up with the network. Nodes with limited resources (e.g., 2-core systems) may see block generation slow from 3.7 seconds to over 33 seconds under attack. The attack does not result in fund loss or consensus faults but disrupts normal operation until the attacker stops sending transactions.

Compliance Impact

This vulnerability primarily causes availability issues by stalling block verification, which may disrupt normal operations for nodes with limited resources. While it does not directly impact data confidentiality or integrity, prolonged downtime could interfere with logging, auditing, or transaction processing required by standards like GDPR or HIPAA.

Mitigation Strategies

Upgrade Zebra to version 6.2.1 or later immediately. If unable to upgrade, restrict inbound peer connections to trusted nodes to reduce exposure. Monitor node performance closely for signs of attack.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104423. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart