<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Zebra (&lt; 6.3.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/zebra--6.3.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 12:24:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/zebra--6.3.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service via Unvalidated Coinbase Height in Zebra (zebrad)</title><link>https://feed.craftedsignal.io/briefs/2026-10-zebrad-dos/</link><pubDate>Fri, 02 Oct 2026 12:24:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-zebrad-dos/</guid><description>An unvalidated coinbase height input in Zebra prior to 6.3.0 allows malicious peers to induce synchronization stalls and prevent nodes from reaching the latest chain tip.</description><content:encoded><![CDATA[<p>Zebra (zebrad) versions before 6.3.0 contain a vulnerability in the block sync download path that allows remote attackers to perform a Denial of Service (DoS) attack. The issue stems from the node reading a block's height directly from an unvalidated coinbase scriptSig. Because V5 transaction IDs in this protocol exclude the scriptSig, an attacker can manipulate the reported height in the coinbase while maintaining a canonical block hash. By serving blocks that claim an incorrect height (e.g., height 1) while requesting the latest chain tip, a malicious peer can force the target node to drop blocks that appear too far behind the current state. Crucially, the node fails to penalize the source of these invalid blocks, allowing the attacker to repeatedly stall the victim's synchronization progress and prevent the node from discovering the actual newest block on the network. This impacts the availability and consensus participation of affected nodes.</p>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of CVE-2026-104422 results in a persistent denial-of-service condition for Zebra nodes. Affected nodes may fail to synchronize with the network, preventing them from validating or relaying transactions and blocks. This could lead to a loss of network participation and availability for services relying on Zebra, with potential impacts on transaction latency and node reliability within the Zcash ecosystem.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Zebra (zebrad) to version 6.3.0 or later to ensure proper validation of block heights during synchronization.</li>
<li>Monitor logs for repeated sync failures or blocks rejected due to height discrepancies from specific peer IP addresses.</li>
<li>Implement network-level rate limiting or peer reputation management to identify and disconnect peers frequently transmitting invalid block data.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>