CVE-2026-104425
Received Received - Intake

Zebra Blockchain Resource Exhaustion via Invalid Orchard Proofs

Vulnerability report for CVE-2026-104425, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zcashfoundation zebra to 6.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-405 The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104425 is a denial-of-service (DoS) vulnerability in ZcashFoundation's Zebra software versions before 6.1.0. It allows unauthenticated peers to degrade block processing by submitting transactions with invalid Orchard proofs. These invalid proofs force the shared batch verifier to switch to slower individual verification, reducing block processing speed by about seven times.

Detection Guidance

Detecting this vulnerability requires monitoring Zebra node logs for repeated Orchard proof verification failures or unusual batch processing delays. Check for peers sending invalid transactions without being penalized. Use Zebra's built-in metrics or logging to track block processing times and verification failures.

Impact Analysis

This vulnerability can degrade network performance by slowing block processing, potentially causing delays in transaction confirmations. It does not crash systems or corrupt data but may reduce overall network efficiency. Users may experience slower transaction validations and potential service disruptions if the attack is sustained.

Compliance Impact

This vulnerability primarily impacts system availability by degrading block processing performance through denial-of-service attacks. It does not directly affect data confidentiality or integrity, which are key focus areas for GDPR and HIPAA. However, prolonged system unavailability could indirectly impact compliance if it disrupts services handling protected data.

Mitigation Strategies

Upgrade Zebra to version 6.1.0 or later immediately. No configuration-only workaround exists. Ensure your node is running the patched version to attribute verification failures to peers and enable misbehavior scoring.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104425. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart