Sceawere

Vulnerability Detail

CVE-2026-104423UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebra Halo2 Proof Verification Denial-of-Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Asymmetric Resource Consumption (Amplification)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-02T12:17:12.433Z",
  "pubdate": "2026-10-02T12:17:12.433Z",
  "executiveSummary": "Zebra (zebrad) prior to version 6.2.1 is susceptible to an asymmetric resource consumption vulnerability characterized as a Denial-of-Service (DoS) vector.\nThe vulnerability originates from the handling of V6 mempool transactions, specifically those containing invalid Halo2 proofs.\nUnauthenticated peers can exploit this flaw by flooding the node's shared, unprioritized Halo2 verification queue with high volumes of zero-fee transactions populated with zero-filled Orchard and Ironwood proofs.\nThis behavior forces the node to expend significant computational resources validating fraudulent proofs, resulting in a performance bottleneck that prevents the node from processing legitimate chain data.\nThe primary impact is the stalling of block verification, which causes affected nodes to fall behind the canonical chain tip, effectively resulting in service disruption.\nSuccessful exploitation requires no prior authentication and can be performed remotely by any peer within the network, making it a high-risk vector for node synchronization degradation.",
  "technicalDetails": "The vulnerability exists within the zebrad block and transaction verification pipeline, specifically concerning the processing of Halo2 proofs associated with V6 transactions. The architecture utilizes a shared verification queue for incoming mempool transactions, which lacks sufficient prioritization or rate-limiting mechanisms for the computationally intensive Halo2 proof validation process.\nThe root cause is an imbalance between the computational cost of verifying a Halo2 proof and the ease of submitting such proofs for validation. Because the verification queue is unprioritized, an attacker can saturate the queue with malicious payloads that appear syntactically correct but contain zero-filled or otherwise invalid proof data for Orchard and Ironwood protocols.\nExploitation follows a systematic attack flow: First, the attacker crafts a series of V6 mempool transactions that require Halo2 proof verification. Second, the attacker populates these transactions with zero-filled Orchard or Ironwood proofs, intentionally triggering validation failure but consuming CPU cycles during the attempt. Third, the attacker broadcasts these transactions to the target zebrad node without requiring authentication.\nUpon receipt, the target node places these transactions into the shared Halo2 verification queue. Because the queue does not distinguish between legitimate and junk proofs, it processes these malicious transactions in the order they are received. The intensive cryptographic operations required to validate Halo2 proofs ensure that the CPU becomes fully occupied with invalid workloads. This prevents the node from dedicating resources to verifying legitimate block headers and transactions, causing the node to lag behind the current chain tip.\nSince the verification process is computationally expensive, a relatively small number of malicious transactions can effectively stall the entire block verification pipeline. This asymmetric nature—where the attacker's cost to submit the proof is negligible compared to the node's cost to verify it—is the core mechanism of the denial-of-service condition. This vulnerability affects all zebrad versions prior to 6.2.1 and requires no network-level elevation or specific privileges, as it targets the standard p2p transaction propagation and validation mechanisms."
}
CVE-2026-104423: Zebra Halo2 Proof Verification Denial-of-Service (HIGH Severity, CVSS: 7.5) | Sceawere