CVE-2026-104428
Received Received - Intake

Zebra Node Panic via RPC getblock Method

Vulnerability report for CVE-2026-104428, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zcash_foundation zebra to 11.0.0 (exc)
zcash_foundation zebra_rpc to 11.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104428 is a denial-of-service vulnerability in Zebra, a Zcash node software. It occurs when the getblock RPC method is called with verbosity set to 2 on a side-chain block with -1 confirmations. The node crashes because it tries to convert -1 to an unsigned 32-bit integer, which fails and triggers a panic.

Detection Guidance

Monitor for repeated crashes of the Zebra node process when the getblock RPC method is called with verbosity=2. Check logs for panic messages related to u32 conversion failures or side-chain blocks with -1 confirmations.

Impact Analysis

Remote unauthenticated attackers can exploit this to crash Zebra nodes repeatedly, causing a denial-of-service. The node recovers after each crash but remains unavailable until restarted. Attackers can use lightwalletd or direct RPC access to trigger the issue.

Compliance Impact

This vulnerability primarily impacts availability by causing a denial-of-service condition through repeated crashes of the Zebra node. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, prolonged downtime could disrupt services handling regulated data, potentially leading to compliance issues if availability requirements are not met.

Mitigation Strategies
  • Upgrade Zebra to version 11.0.0 or later to patch the vulnerability.
  • Disable or restrict access to the getblock RPC endpoint, especially if exposed to untrusted networks.
  • Enable RPC cookie authentication to add a layer of access control.
  • Avoid exposing the RPC port directly to the internet or limit it to trusted IPs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104428. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart