CVE-2026-104436
Received Received - Intake

Zebra P2P Block Locator Vector Resource Exhaustion

Vulnerability report for CVE-2026-104436, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
zebra zebra to 4.5.0 (exc)
zebra zebrad to 4.4.1 (exc)
zebra zebra-chain to 6.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Zebra before 4.5.0 allows remote P2P peers to cause CPU exhaustion by sending oversized block locator vectors in getblocks or getheaders messages. Attackers can include up to 65,535 locator hashes, forcing excessive chain lookups that degrade block validation, RPC, and mempool performance.

Detection Guidance

Monitor Zebra node logs for excessive CPU usage or repeated getblocks/getheaders requests with large locator vectors. Check for blocked threads in blocking-pool during P2P message handling. Use network monitoring tools to detect peers sending oversized block locator vectors.

Impact Analysis

This vulnerability can degrade system performance by consuming CPU resources through excessive chain lookups. It may slow down block validation, RPC responses, and mempool operations, especially under sustained attack from multiple peers. Exploitation requires significant attacker bandwidth and multiple Sybil peers.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it pertains to resource exhaustion in a blockchain node software (Zebra). However, if exploited, degraded performance could indirectly impact systems handling sensitive data by reducing availability or response times, potentially violating availability requirements in GDPR (Article 32) or HIPAA (Security Rule). No direct compliance violations are specified in the provided context.

Mitigation Strategies

Upgrade Zebra to version 4.5.0 or later to apply the patch that caps locator vector length at 101 entries. If upgrading is not immediately possible, restrict P2P connections to trusted peers or disable P2P functionality temporarily.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104436. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart