CVE-2026-104434
Received Received - Intake

Zebra RPC Handler Assertion Failure in ZcashFoundation Zebra

Vulnerability report for CVE-2026-104434, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
zcashfoundation zebra to 8.0.0 (exc)
zcashfoundation zebrad to 4.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Denial of Service (DoS) flaw in ZcashFoundation's Zebra node software. It occurs in the z_listunifiedreceivers RPC handler, where an assertion fails when processing Unified Addresses with invalid Jubjub points. Authenticated RPC clients can exploit this by submitting a malformed address, causing the zebrad process to crash and repeatedly keep the node offline.

Detection Guidance

To detect this vulnerability, monitor for crashes in Zebra or zebrad processes after processing RPC requests. Check logs for assertions or panics related to z_listunifiedreceivers. Ensure RPC authentication is enforced and inspect network traffic for malformed Unified Addresses sent to the RPC endpoint.

Impact Analysis

If you run a vulnerable Zebra node (zebra-rpc before 8.0.0 or zebrad before 4.5.0), an attacker with RPC access can crash your node repeatedly, making it unavailable indefinitely. This requires authentication, which may be possible via local file access or network if cookie authentication is disabled.

Compliance Impact

This vulnerability primarily causes a Denial of Service (DoS) by crashing the Zebra node, which could disrupt availability of services handling sensitive data. For GDPR, this may impact the right to access or rectify data if services become unavailable. For HIPAA, it could affect the availability of protected health information systems. However, the CVE does not explicitly link this issue to compliance violations.

Mitigation Strategies

Immediately upgrade to Zebra 8.0.0+ or zebrad 4.5.0+. Disable the RPC server if not needed. If RPC is required, enforce secure cookie authentication and filter malicious requests upstream. Ensure proper error handling is implemented in RPC handlers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104434. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart