CVE-2026-104429
Received Received - Intake

Zebra Daemon Mempool Admission Bypass via P2P Tx Flood

Vulnerability report for CVE-2026-104429, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zebra zebrad From 0 (inc) to 6.0.0-rc.0 (exc)
zebra zebrad to 6.0.0-rc.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104429 affects Zebra versions before 6.0.0-rc.0. It allows a remote inbound peer to send many unique transactions via direct P2P messages, bypassing per-peer mempool admission caps. Normally, Zebra limits each peer to 5 concurrent mempool admissions, but direct transaction messages lack sender peer data, enabling unfair mempool slot occupation. This disrupts transaction relay by crowding out honest peers' transactions.

Detection Guidance

Monitor Zebra mempool usage and P2P transaction traffic. Check for unusually high transaction volumes from single peers or excessive mempool occupancy. Use Zebra's built-in metrics or logs to track per-peer admission counts and global mempool limits.

Impact Analysis

This vulnerability can degrade network performance by delaying or dropping legitimate transactions. Affected nodes may experience increased CPU and memory usage due to unnecessary transaction verification. It primarily impacts availability and relay functionality rather than confidentiality or integrity. Users running vulnerable Zebra versions risk reduced transaction processing efficiency.

Compliance Impact

This vulnerability primarily impacts system availability and transaction relay performance by allowing malicious peers to consume disproportionate mempool resources. It does not directly affect confidentiality or integrity of data, which are key concerns for GDPR and HIPAA. However, degraded availability could indirectly impact compliance by disrupting transaction processing or audit trails in systems where timely relay is required.

Mitigation Strategies
  • Upgrade Zebra to version 6.0.0-rc.0 or later to patch the vulnerability.
  • Disable inbound P2P connections temporarily if upgrading is not immediate.
  • Restrict P2P peers to trusted hosts to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104429. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart