CVE-2026-104432
Received Received - Intake

Zebra Node Improper Tip Status Handling Vulnerability

Vulnerability report for CVE-2026-104432, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zebra zebra to 6.3.0 (exc)
zebra chain_sync to 6.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zebra before version 6.3.0 has a flaw in ChainSync::obtain_tips that incorrectly discards valid one-hash FindBlocks responses. When peers send only the next block hash, the node records a zero-length sync sample, falsely indicating it is close to the tip. This causes the /ready endpoint to return 200 OK even though the node is behind the chain tip.

Detection Guidance

Check Zebra node version with zebrad --version. Verify /ready endpoint responses by comparing node's reported tip height with network tip height using zebra-cli get-tip-height. Monitor sync status via zebra-cli get-blockchain-info for zero-length sync samples.

Impact Analysis

This vulnerability can mislead dependent systems like load balancers or monitoring tools into thinking a Zebra node is ready when it is actually behind the chain tip. This may cause incorrect routing of requests or failure to detect sync issues, potentially leading to stale data being served or missed updates.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR, HIPAA, or similar standards as it does not involve unauthorized data access, disclosure, or processing violations. The issue relates to a false readiness status in a blockchain node, which could mislead monitoring systems but does not compromise data integrity or security controls required by these regulations.

Mitigation Strategies

Upgrade Zebra to version 6.3.0 or later. If unable to upgrade, manually verify chain tip height against network peers. Ensure monitoring systems do not rely solely on /ready endpoint status.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104432. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart