CVE-2026-104421

Published: Ott 02, 2026 Last Modified: Ott 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,9
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,3
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: low

Description

AI Translation Available

Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.

459

Incomplete Cleanup

Draft
Common Consequences
Security Scopes Affected:
Other Confidentiality Integrity
Potential Impacts:
Other Read Application Data Modify Application Data Dos: Resource Consumption (Other)
Applicable Platforms
All platforms may be affected
View CWE Details
https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-x93j-mj2f-q338
https://www.vulncheck.com/advisories/zebra-before-6.2.1-block-download-denial-o…