Skip to content
Threat Feed
low advisory

Denial of Service via Asymmetric Resource Consumption in Zebrad

Unauthenticated remote peers can exploit a vulnerability in Zebrad versions prior to 6.2.1 by submitting mempool transactions with invalid Halo2 proofs, leading to a denial-of-service condition.

CVE search metadata

CVE search record: CVE-2026-104423. Severity: high. CVSS: 7.5. KEV: no. Brief: Denial of Service via Asymmetric Resource Consumption in Zebrad. Brief link: https://feed.craftedsignal.io/briefs/2026-10-zebra-resource-exhaustion/

Zebra (zebrad) versions before 6.2.1 are vulnerable to an asymmetric resource consumption vulnerability (CVE-2026-104423). This flaw allows unauthenticated remote peers to stall the block verification process by submitting specifically crafted mempool transactions. By flooding the node's shared, unprioritized Halo2 verification queue with zero-fee transactions that utilize zero-filled Orchard and Ironwood proofs, an attacker can consume significant node