Sceawere

Vulnerability Detail

CVE-2026-104421UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebra Incomplete Cleanup Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Incomplete Cleanup
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T12:17:12.143Z",
  "pubdate": "2026-10-02T12:17:12.143Z",
  "executiveSummary": "Zebra versions prior to 6.2.1 are susceptible to an incomplete cleanup vulnerability involving the peer-to-peer block synchronization mechanism.\nThe vulnerability allows an unauthenticated remote attacker to perform a targeted Denial of Service (DoS) attack by preventing a node from downloading valid blockchain blocks.\nBy manipulating the 'SentHashes' tracking structure, an attacker can induce a state where the victim node erroneously believes it has already processed or is currently aware of a block, causing the node to skip synchronization of legitimate data.\nThis effectively keeps the affected node behind the network tip, isolating it from the canonical chain. The exploitation does not require prior authentication or privileged access, relying solely on the ability of an attacker to interact with the Zebra peer network.\nThe impact is significant for network consensus, as it degrades the node's ability to maintain a synchronized state, thereby limiting its utility and potentially its security within the distributed network.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper state management of the 'SentHashes' cache within the block propagation logic of Zebra. In the affected versions, when a peer submits a contextually invalid block that shares the same header hash as a legitimate, honest block, the internal cleanup routine fails to correctly handle the resulting conflict.\nThe vulnerability manifests within the 'Request::KnownBlock' function. When a node receives a block transmission, it checks its local cache of previously processed or advertised hashes to determine if the block is already known. If an attacker intentionally transmits an invalid block, the 'SentHashes' map is updated with the hash of that invalid payload.\nBecause the cleanup process is incomplete, the rejected hash persists in the 'SentHashes' registry. When the victim node subsequently receives an announcement or a legitimate request for the valid block sharing that same header hash, 'Request::KnownBlock' references the corrupted state in 'SentHashes'. Finding the hash already present, the function incorrectly concludes that the block is already processed or 'known', causing the node to skip the download attempt entirely.\nThe attack flow is as follows: 1) The attacker observes or predicts a valid block header hash on the network. 2) The attacker crafts a contextually invalid block that utilizes this specific hash. 3) The attacker broadcasts this invalid block to the victim node. 4) The victim node adds this invalid hash to 'SentHashes' during the ingestion attempt. 5) When the legitimate block arrives via honest peers, the 'Request::KnownBlock' logic triggers a false positive hit in the tracking structure. 6) The valid block is dropped, and the node fails to advance its blockchain state. 7) The victim remains permanently stuck behind the network tip until the stale entry is cleared or the node is restarted.\nThis vulnerability exploits the trust assumption inherent in the block advertisement protocol where header hashes are treated as identifiers for the presence of the full data. Since there is no authentication required for the initial block announcement, the attack vector is fully exposed to any node capable of communicating with the target via the standard network protocol."
}
CVE-2026-104421: Zebra Incomplete Cleanup Denial of Service (MEDIUM Severity, CVSS: 5.3) | Sceawere