Sceawere

Vulnerability Detail

CVE-2026-104434UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebra RPC Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Reachable Assertion
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-02T12:17:13.917Z",
  "pubdate": "2026-10-02T12:17:13.917Z",
  "executiveSummary": "This vulnerability is a reachable assertion failure within the Zebra RPC interface, specifically affecting the z_listunifiedreceivers handler. The flaw exists in the parsing logic for Unified Addresses containing invalid Jubjub points. By submitting a maliciously crafted address, an authenticated RPC client can trigger an unhandled panic, leading to a repeatable denial-of-service (DoS) condition.\nThe vulnerability affects ZcashFoundation Zebra, specifically zebrad versions prior to 4.5.0 and zebra-rpc components prior to 8.0.0. The risk is significant as it allows a remote, authenticated attacker to intentionally crash the node process, thereby disrupting network participation and service availability. Exploitation does not require elevated system privileges beyond valid RPC authentication credentials. Because the crash occurs during the processing of the RPC request, the node is rendered offline, requiring manual intervention to restore the service. Given that Zebra is a consensus-critical component of the Zcash network, this vulnerability presents a direct threat to the availability of the node, which may have broader implications for network synchrony if widespread exploitation were attempted.",
  "technicalDetails": "The root cause of this vulnerability lies in the improper handling of cryptographic input within the z_listunifiedreceivers RPC method. Specifically, the implementation utilizes the expect() function when attempting to parse Sapling receivers embedded within a Unified Address. In Rust, the expect() function is designed to trigger an immediate process abort (panic) if the underlying Result or Option type returns an error. This pattern is unsuitable for processing external, untrusted input where error states are expected.\nThe attack flow begins when an authenticated client sends a JSON-RPC request to the z_listunifiedreceivers endpoint. The payload includes a Unified Address containing a Sapling receiver with an invalid Jubjub point. As the zebrad process parses this address, the internal cryptographic validation logic encounters the malformed point and returns an error. Instead of propagating this error gracefully through the RPC response handler, the code calls expect() on the failing result, causing the entire zebrad daemon to terminate unexpectedly.\nThe vulnerability resides in the zebra-rpc crate, which provides the RPC interface for the zebrad node software. Because the RPC interface is often exposed to manage node operations, an attacker with valid RPC credentials can repeatedly exploit this behavior. The impact is a persistent denial-of-service; because the node must be restarted to resume operation, and the attack can be automated, a malicious actor can maintain a continuous state of downtime for the targeted node.\nAffected versions include Zebra releases where zebrad is below 4.5.0 and zebra-rpc is below 8.0.0. The exploitation process is highly reliable as it relies on deterministic behavior of the Rust panic mechanism. Since the crash occurs during input validation, it bypasses standard error handling layers, effectively terminating the application lifecycle. There is no recovery or error recovery path defined within the vulnerable handler that would allow the application to continue running after the assertion failure. Consequently, the node process stops execution immediately upon encountering the malformed input, demonstrating that the issue is not merely a logic error but a fundamental failure to sanitize input before passing it to critical, panic-inducing primitives."
}
CVE-2026-104434: Zebra RPC Denial of Service (MEDIUM Severity, CVSS: 6.5) | Sceawere