Sceawere

Vulnerability Detail

CVE-2026-104436UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebra Uncontrolled Resource Consumption Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-10-02T12:17:14.210Z",
  "pubdate": "2026-10-02T12:17:14.210Z",
  "executiveSummary": "Zebra versions prior to 4.5.0 are susceptible to an uncontrolled resource consumption vulnerability stemming from inadequate validation of P2P network messages.\nThis vulnerability is classified as an uncontrolled resource consumption issue that allows remote, unauthenticated P2P peers to exhaust the application's internal blocking-pool threads.\nBy transmitting specially crafted 'getblocks' or 'getheaders' messages containing an excessive number of locator hashes, an attacker can force the system to initiate intensive, per-hash chain lookups.\nThis behavior results in a significant degradation of critical node functions, including block validation, RPC responsiveness, and mempool synchronization.\nThe attack is remotely exploitable without requiring authentication, posing a severe threat to node availability and network stability.\nRisk implications include potential denial-of-service scenarios where a node becomes unable to process legitimate blockchain synchronization requests or maintain proper network connectivity due to thread starvation.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient input validation of block locator vectors within the P2P networking layer of Zebra versions prior to 4.5.0.\nIn the Zebra P2P protocol, 'getblocks' and 'getheaders' messages utilize a vector of locator hashes to facilitate chain synchronization between peers.\nThe implementation fails to enforce reasonable constraints on the length of these vectors, allowing an attacker to include up to 65,535 locator hashes in a single message.\nWhen a node receives such an oversized message, it attempts to process each hash individually through its internal thread pool designated for blocking operations.\nThe exploitation flow proceeds as follows: First, a remote attacker establishes a P2P connection to the targeted Zebra node. Second, the attacker transmits a malformed 'getblocks' or 'getheaders' message containing the maximum permitted number of locator hashes.\nThird, the application logic triggers an individual chain lookup operation for every provided hash. Because these operations are CPU and I/O intensive and are handled by the blocking-pool, the large volume of requests quickly saturates the available thread pool.\nThis thread starvation directly inhibits the node's ability to perform routine block validation, respond to RPC requests, or update the mempool, as these tasks must wait for available threads in the exhausted pool.\nThe lack of rate limiting or size validation on these vectors makes the node highly sensitive to this resource exhaustion attack. The impact is a form of distributed or singular denial-of-service, where the node's performance is severely degraded, potentially causing it to drop out of sync with the rest of the network or time out legitimate peer connections.\nThis vulnerability does not require any specialized privileges or previous authentication, as it leverages standard P2P message exchange protocols exposed by the node to any connected peer."
}
CVE-2026-104436: Zebra Uncontrolled Resource Consumption Vulnerability (LOW Severity, CVSS: 3.7) | Sceawere