Sceawere

Vulnerability Detail

CVE-2026-104428UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebra RPC Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Reachable Assertion
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-02T12:17:13.177Z",
  "pubdate": "2026-10-02T12:17:13.177Z",
  "executiveSummary": "The Zebra node implementation is vulnerable to a remotely exploitable Denial of Service (DoS) condition within its JSON-RPC interface.\nThe vulnerability originates in the getblock RPC method, specifically when processing side-chain blocks with a verbosity setting of 2.\nA failure in integer type conversion leads to an unhandled panic, resulting in an immediate process termination.\nBecause the service lacks robust error handling for this specific RPC input, remote unauthenticated attackers—including those interacting via lightwalletd—can trigger the crash repeatedly.\nSuccessful exploitation induces a sustained crash loop, effectively rendering the affected Zebra node unavailable for block synchronization or transaction processing.\nThis vulnerability poses a significant risk to network availability for nodes running versions prior to 11.0.0, as it allows for trivial remote disruption without requiring authentication or elevated privileges.",
  "technicalDetails": "The vulnerability resides in the getblock RPC method handling logic within the Zebra-rpc component, which fails to safely process block confirmation data when a side-chain block is queried.\nWhen a user invokes getblock with 'verbosity' set to 2, the node attempts to calculate or retrieve the number of confirmations for the requested block. For blocks located on a side-chain, the node assigns a sentinel value of -1 to represent the confirmation status.\nThe implementation attempts to cast this signed integer sentinel value into an unsigned 32-bit integer (u32) type using the .expect() method. In Rust, calling .expect() or .unwrap() on a conversion failure causes an immediate thread or process panic if the value cannot be represented in the destination type. Since -1 cannot be represented as a u32, the conversion fails, and the process terminates abruptly.\nThe attack flow is straightforward: an attacker identifies a side-chain block hash (or waits for the node to reorganize) and submits a JSON-RPC request to the getblock method with verbosity=2. The node receives the request, attempts to generate the response object, hits the problematic casting logic, and crashes.\nBecause the RPC interface does not require authentication, the attack surface is exposed to any entity capable of establishing a network connection to the RPC port. Furthermore, since lightwalletd acts as a gateway for many wallet interactions, requests passed through the lightwalletd layer also trigger the same vulnerable code path in the underlying Zebra node.\nThe exploitation does not require advanced memory corruption techniques or heap spraying; it is a logic-based fault that triggers a standard panic. Attackers can automate the submission of these malicious RPC calls, ensuring the Zebra node enters a persistent crash loop, thereby effectively partitioning the node from the network and preventing it from performing its core duties.\nAffected versions include all Zebra node releases prior to 11.0.0. The lack of proper error handling in the RPC response construction logic represents the root cause, allowing for a trivial bypass of service availability through standard protocol interaction."
}
CVE-2026-104428: Zebra RPC Denial of Service (MEDIUM Severity, CVSS: 5.3) | Sceawere