Sceawere
Vulnerability Detail
CVE-2026-104429UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zebra Mempool Admission Cap Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 11h ago
- Vendor
- ZcashFoundation
- Product
- zebra
- Attack Type
- Allocation of Resources Without Limits or Throttling
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-02T12:17:13.323Z",
"pubdate": "2026-10-02T12:17:13.323Z",
"executiveSummary": "The Zebra (zebrad) daemon, in versions 5.0.0 through 6.0.0-rc.0, contains a critical flaw in its mempool admission control logic. Specifically, the application fails to enforce per-peer mempool admission limits for transactions received via direct P2P transaction messages.\nThis vulnerability is classified as an improper input validation and resource management flaw. By exploiting this oversight, a remote, unauthenticated attacker can flood the node with a high volume of unique, unsolicited transactions. Because the system fails to associate these incoming P2P messages with a specific source peer, it cannot throttle or cap the number of transactions accepted from any single connection.\nThe primary impact is a targeted Denial of Service (DoS) against the mempool, where an attacker can consume a disproportionate share of mempool slots. This behavior effectively crowds out legitimate transactions from honest peers, preventing them from being relayed or included in blocks. This attack is remotely exploitable without authentication, requiring only an established P2P connection to the affected node. The risk is significant as it degrades the network relay functionality of the Zebra node.",
"technicalDetails": "The root cause of this vulnerability lies in the decoupling of transaction reception from source-tracking metadata within the Zebra mempool admission process. In the affected versions, the zebrad P2P subsystem processes incoming 'tx' messages as independent entities that are queued for mempool inclusion without properly attributing the message to the peer that transmitted it.\nUnder normal operating conditions, mempool admission caps are enforced to prevent any single peer from saturating the node's memory resources. These caps rely on maintaining a context where the sending peer's identifier is known and tied to the incoming transaction buffer. Due to the architectural oversight in Zebra, the transaction relay logic bypasses the per-peer accounting mechanism when receiving direct P2P transaction messages.\nThe attack flow proceeds as follows: First, an attacker establishes a network connection to a victim zebrad node via the standard P2P protocol. Second, the attacker initiates a flood of unique, high-frequency transaction messages. Third, because the node fails to map these transactions to the attacker's peer ID, the mempool admission logic treats these as anonymous inputs and fails to decrement the attacker's remaining allowed transaction quota. Fourth, the mempool slots become saturated by the attacker's data, causing the node to reject or delay legitimate transactions submitted by honest peers, effectively causing a mempool-level Denial of Service.\nThe vulnerability affects Zebra versions 5.0.0 up to, but not including, 6.0.0-rc.0. The flaw is present in the transaction handling logic where the message queue is populated. There are no authentication or privilege requirements for an attacker to initiate this exploit, provided the node has open P2P port exposure to the internet or the attacker's local network. The post-exploitation impact includes the degradation of the node's ability to facilitate network relay, causing potential synchronization issues and reduced network stability for the victimized node."
}