Sceawere
Vulnerability Detail
CVE-2026-104425UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zebra Orchard Proof Exhaustion Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 11h ago
- Vendor
- ZcashFoundation
- Product
- zebra
- Attack Type
- Asymmetric Resource Consumption (Amplification)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T12:17:12.730Z",
"pubdate": "2026-10-02T12:17:12.730Z",
"executiveSummary": "ZcashFoundation Zebra versions prior to 6.1.0 are susceptible to a resource exhaustion vulnerability within the Orchard proof verification subsystem.\nThe vulnerability stems from an improper handling of invalid Orchard proofs, which allows unauthenticated remote peers to bypass the misbehavior-scoring mechanism.\nBy submitting malformed transactions containing invalid proofs, an attacker can force the system to revert from high-efficiency batch verification to a computationally expensive individual verification path.\nThis behavior induces a significant denial-of-service (DoS) condition by degrading block processing throughput by approximately sevenfold.\nThe attack is remotely exploitable without authentication, posing a severe risk to network availability and node synchronization performance.\nThe vulnerability resides in the interaction between the network layer and the halo2 batch verifier, where the failure to penalize peers for invalid cryptographic proofs facilitates repetitive exploitation cycles.",
"technicalDetails": "The vulnerability is situated within the Orchard proof validation pipeline of the Zebra node software. Zebra utilizes the halo2 proof system for efficient block verification, which typically employs batch verification to validate multiple proofs simultaneously. This mechanism significantly reduces the CPU overhead required to process blocks containing high volumes of Orchard transactions.\nThe root cause of this vulnerability is a flaw in the validation logic that fails to assign misbehavior scores to peers transmitting invalid Orchard proofs. Under normal operation, nodes are expected to apply penalties to peers that propagate invalid data; however, the lack of scoring for these specific malformed proofs allows an attacker to continuously flood the node with invalid transactions without triggering network bans or connection termination.\nThe exploitation flow proceeds as follows: An attacker sends a series of transactions containing invalid Orchard proofs to a target Zebra node. Because the proofs are invalid, the shared halo2 batch verifier fails to validate them in aggregate. Instead of triggering a punitive action, the Zebra node's validation logic defaults to the individual-verification fallback path for these proofs. The individual-verification path is computationally intensive and bypasses the efficiency gains of the batch verifier.\nBy repeatedly injecting these invalid proofs, the attacker forces the node to exclusively utilize this slow, individual-verification path for a disproportionate amount of time. This results in a roughly sevenfold degradation in block processing speed. This resource exhaustion effectively stalls the node's ability to sync with the network or process legitimate transactions in a timely manner, facilitating a denial-of-service attack on the peer-to-peer (P2P) infrastructure.\nThis vulnerability is particularly impactful because it requires zero authentication and relies on standard P2P protocol interactions to inject the payload. The affected component is the integration layer between the network stack and the halo2 cryptographic proof verifier, which fails to enforce sufficient input validation and peer accountability for cryptographic failures prior to version 6.1.0."
}