Sceawere
Vulnerability Detail
CVE-2026-104424UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zebra Block Template Selection Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 11h ago
- Vendor
- ZcashFoundation
- Product
- zebra
- Attack Type
- Incorrect Calculation of Buffer Size
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-10-02T12:17:12.580Z",
"pubdate": "2026-10-02T12:17:12.580Z",
"executiveSummary": "Zebra software versions prior to 6.1.0 are affected by an incorrect calculation vulnerability within the ZIP-317 block template selector component. This flaw stems from a failure to account for block header and transaction-count sizes when computing the overall block budget during template generation. Consequently, remote attackers can exploit this behavior by introducing carefully structured, valid selectable transactions into a target miner's mempool. When the vulnerable Zebra node constructs a block template, it aggregates these transactions without reserving space for the header and counter, leading to the creation of oversized blocks. Miners utilizing these flawed templates will expend valuable computational energy solving proof-of-work puzzles for blocks that are fundamentally invalid under network consensus rules. Upon propagation, the network rejects these oversized blocks, resulting in complete loss of the associated block rewards and wasted mining resources. Exploitation does not require elevated privileges or authentication, as the attack is executed through standard transaction propagation mechanisms in the public mempool, posing a significant economic threat to affected miners.",
"technicalDetails": "The vulnerability is located within Zebra's implementation of the ZIP-317 standard, which governs transaction selection and fee mechanics for block construction. During the block template creation process, a Zebra node must select transactions from its local mempool and assemble them into a block payload that respects the maximum consensus size limits. The root cause of this vulnerability is an incorrect budget calculation algorithm within the ZIP-317 block template selector. Specifically, the selector evaluates the remaining block capacity solely based on the sizes of the chosen transactions, completely omitting the bytes required for the block header and the transaction-count field.\nBecause these critical structural elements are excluded from the mathematical budget model, the algorithm calculates a false ceiling for transaction capacity. This allows the selector to pack transactions up to the absolute limit, leaving zero byte headroom for the mandatory overhead.\nAn attacker can systematically exploit this logical omission via the following attack flow:\n1. The attacker analyzes the target network's consensus rules and determines the precise byte thresholds required to push a block template over the maximum allowed size limit when header and transaction-count overhead are appended.\n2. The attacker crafts a series of valid, standard transactions that conform to ZIP-317 selection criteria, ensuring they are highly attractive to the template selector.\n3. These transactions are broadcasted to the target miner's mempool.\n4. When the victim's Zebra node (running a version prior to 6.1.0) invokes its block template generator, the ZIP-317 selector pulls these transactions. Because the budget calculation ignores the block header and transaction-count sizes, it fills the transaction space up to the maximum limit.\n5. The node completes the block template construction by appending the block header and transaction count. This final step pushes the total block size beyond the strict network consensus limit, rendering the template invalid.\n6. The miner, unaware of the structural invalidity, consumes significant electrical and computational resources executing proof-of-work (PoW) algorithms to find a valid block hash.\n7. Once a solution is found, the miner attempts to propagate the solved block to the network.\n8. Peer nodes validate the incoming block, identify that its total size violates consensus constraints, and immediately reject it.\nAs a result of this attack flow, the victim miner suffers a total loss of the block reward and transaction fees for the solved block, alongside wasted operational expenditures on proof-of-work computation."
}