CVE-2026-104426
Received Received - Intake

Inefficient Algorithmic Complexity in Zebra Blockchain

Vulnerability report for CVE-2026-104426, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zebra zebra to 6.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-407 An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104426 is a denial-of-service vulnerability in Zebra versions before 6.1.0 caused by inefficient algorithmic complexity in the remaining_transaction_value function. During block validation, the function clones the entire spent-UTXO map for each transaction, leading to excessive processing time. Attackers can exploit this by submitting around 26,000 minimal transactions in one block, stalling validating nodes for over 52 seconds.

Detection Guidance

To detect this vulnerability, monitor Zebra node performance during block validation. Look for unusual delays exceeding 52 seconds when processing blocks with high transaction volumes. Check for high CPU usage or memory spikes during contextual verification. No specific commands are provided in the resources, but you can observe node logs for stalled validation processes.

Impact Analysis

This vulnerability can cause validating nodes to experience significant processing delays during block validation, leading to temporary performance degradation. While it does not crash nodes or corrupt data, it can disrupt network operations by slowing down transaction processing. Node operators running vulnerable Zebra versions may face reduced efficiency during peak attack scenarios.

Compliance Impact

This vulnerability primarily causes denial-of-service conditions by stalling validating nodes for over 52 seconds, which may impact system availability. For compliance standards like GDPR or HIPAA that require timely data processing and system availability, such disruptions could potentially lead to violations if critical operations are delayed or interrupted.

Mitigation Strategies

Immediately upgrade Zebra to version 6.1.0 or later to patch the vulnerability. If upgrading is not possible, restrict network access to prevent malicious transaction seeding and monitor mempool activity for suspicious single-input transactions. Consider temporarily reducing block size limits as a workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104426. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart