CVE-2026-104431
Received Received - Intake

Zebra Node DoS via High-Sigop P2SH Transactions

Vulnerability report for CVE-2026-104431, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zebra zebra to 6.0.0 (exc)
zebra zebra 5.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-405 The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Zebra before version 6.0.0 allows unauthenticated peers to perform a denial of service attack by sending specially crafted mempool transactions. These transactions require expensive synchronous script verification, which can stall Tokio workers and saturate the verifier buffer, making the node unresponsive.

Detection Guidance

To detect this vulnerability, monitor for stalled Tokio workers or unresponsive nodes after receiving non-standard high-sigop P2SH transactions. Check Zebra logs for transactions reaching CachedFfiTransaction::is_valid() before standardness checks. Use network monitoring tools to identify peers sending excessive mempool transactions that block verification.

Impact Analysis

If you run a Zebra node before version 6.0.0, this vulnerability could cause your node to become unresponsive or crash due to the denial of service attack. This disrupts normal operations and may lead to downtime or loss of service for users relying on the node.

Compliance Impact

This vulnerability primarily causes denial of service by stalling node operations, which may impact availability of services handling regulated data. However, the provided context does not specify direct compliance impacts on GDPR or HIPAA beyond potential service disruption.

Mitigation Strategies

Upgrade Zebra to version 6.0.0 or later to address the denial of service vulnerability caused by unauthenticated peers submitting mempool transactions with expensive script verification.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104431. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart