Denial of Service Vulnerability in Zebra
Zebra versions prior to 6.0.0 are vulnerable to an unauthenticated denial-of-service attack via the submission of non-standard high-sigop P2SH transactions that exhaust system resources.
CVE search metadata
CVE search record: CVE-2026-104431. Severity: high. CVSS: 7.5. KEV: no. Product: Zebra (< 6.0.0), Zebra (< 4.4.0). Brief: Denial of Service Vulnerability in Zebra. Brief link: https://feed.craftedsignal.io/briefs/2026-10-zebra-dos/
What's new
- 1. added coverage for Zebra (< 4.4.0) Oct 2, 14:24 via nvd
Zebra versions prior to 6.0.0 contain a denial-of-service (DoS) vulnerability that allows unauthenticated network peers to compromise node stability. The vulnerability stems from the way the node handles mempool transactions; specifically, it allows the submission of non-standard transactions with high signature operation (sigop) counts. These transactions reach the CachedFfiTransaction::is_valid() verification function before standard validation checks are performed. By flooding the node with these computationally expensive transactions, an attacker can saturate the verifier buffer and stall the underlying Tokio workers. This resource exhaustion forces the node to become unresponsive, impacting the availability of the Zebra service. This vulnerability highlights the risk of processing complex transaction data before validating it against standard consensus rules.
Impact
Successful exploitation results in a complete denial of service for the targeted Zebra node. By stalling the Tokio worker threads, the attacker renders the node unable to process legitimate blockchain data, participate in peer-to-peer communication, or perform synchronization tasks, effectively taking the node offline.
Recommendation
Prioritized actions for administrators:
- Patch the affected Zebra software by upgrading to version 6.0.0 or later immediately to address CVE-2026-104431.
- Monitor network traffic and node logs for an unusual influx of high-sigop transactions or sudden spikes in resource utilization (CPU/Memory) corresponding to transaction validation.
- In resource-constrained or critical production environments, implement strict peer admission control or rate limiting for unauthenticated incoming connections to mitigate the impact of malicious transaction bursts until an upgrade is feasible.
Mitigations
Upgrade Zebra to version 6.0.0 or later
CVE-2026-104431