Sceawere

Vulnerability Detail

CVE-2026-104431UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebra Denial of Service Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Asymmetric Resource Consumption (Amplification)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-02T12:17:13.610Z",
  "pubdate": "2026-10-02T12:17:13.610Z",
  "executiveSummary": "A denial of service vulnerability exists in Zebra versions prior to 6.0.0, stemming from improper input validation of mempool transactions. This flaw allows unauthenticated remote attackers to exhaust node resources by submitting specially crafted, non-standard P2SH transactions.\nThe vulnerability manifests because the system triggers synchronous, computationally expensive script verification via CachedFfiTransaction::is_valid() before enforcing standardness constraints. By flooding the verifier buffer with high-signature operation (sigop) payloads, an attacker can stall Tokio workers, effectively rendering the affected Zebra node unresponsive to legitimate network traffic or block processing tasks.\nThe risk implication is significant for node availability, as the attack does not require prior authentication or privileged access, relying solely on the node's willingness to process mempool transactions from peers. Successful exploitation leads to a complete loss of service for the target node, potentially impacting network consensus participation if a sufficient number of nodes are targeted simultaneously.",
  "technicalDetails": "The root cause of this vulnerability lies in the premature invocation of expensive cryptographic and script validation routines during the mempool acceptance process. In Zebra, transactions are submitted for mempool inclusion, where they undergo validation before propagation. The vulnerability resides within the transaction validation pipeline, specifically where CachedFfiTransaction::is_valid() is executed.\nThe attack flow begins when an unauthenticated remote peer injects a non-standard P2SH (Pay-to-Script-Hash) transaction into the node. This payload is engineered to contain a high density of signature operations (sigops). Because the architecture performs expensive synchronous script verification prior to executing standardness checks—such as size constraints or sigop count limits—the node commits significant CPU cycles to the verification of these malicious transactions.\nSince Zebra utilizes the Tokio asynchronous runtime for handling networking and processing, the computational overhead caused by synchronous script verification blocks the underlying thread pool. By continuously submitting these high-sigop transactions, an attacker saturates the verifier buffer. Once the buffer is exhausted and the synchronous verification tasks consume the available Tokio worker threads, the node's ability to schedule and execute other critical tasks is halted.\nThe vulnerable component is identified as the transaction verification logic preceding standardness enforcement. Because this happens before the mempool policy filters are applied, the attacker successfully bypasses initial sanity checks that would normally reject non-standard or oversized transactions. The exploitation does not require the transaction to be valid in the context of the consensus rules, only that it is complex enough to trigger the intensive FFI (Foreign Function Interface) calls involved in CachedFfiTransaction::is_valid().\nPost-exploitation, the node enters a stalled state, where it becomes unresponsive to network requests. This effectively isolates the node from the network, preventing it from relaying blocks or transactions. The impact is a total denial of service, where the node remains unresponsive until the mempool is cleared or the node is restarted, at which point the cycle can be repeated by the attacker."
}
CVE-2026-104431: Zebra Denial of Service Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere