CVE-2026-41585
MEDIUM
6,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnecting before the request body is fully received. The node treats the failure to read the HTTP request body as an unrecoverable error and aborts the process instead of returning an error response. This issue has been patched in zebrad version 4.3.1 and zebra-rpc version 6.0.2.
248
Uncaught Exception
DraftCommon Consequences
Security Scopes Affected:
Availability
Confidentiality
Potential Impacts:
Dos: Crash, Exit, Or Restart
Read Application Data
Applicable Platforms
Languages:
C#, C++, Java
617
Reachable Assertion
DraftCommon Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Crash, Exit, Or Restart
Applicable Platforms
Languages:
C, Java, Not Language-Specific, Rust
Application
Zebra-Rpc by Zfnd
CPE Identifier
View Detailed Analysis
cpe:2.3:a:zfnd:zebra-rpc:1.0.0:beta45:*:*:*:rust:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Zebra-Rpc by Zfnd
CPE Identifier
View Detailed Analysis
cpe:2.3:a:zfnd:zebra-rpc:1.0.0:beta46:*:*:*:rust:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Zebra-Rpc by Zfnd
CPE Identifier
View Detailed Analysis
cpe:2.3:a:zfnd:zebra-rpc:1.0.0:-:*:*:*:rust:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Zebra-Rpc by Zfnd
Version Range Affected
From
2.0.0
(inclusive)
To
6.0.2
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:zfnd:zebra-rpc:*:*:*:*:*:rust:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Zebrad by Zfnd
Version Range Affected
From
2.2.0
(inclusive)
To
4.3.1
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:zfnd:zebrad:*:*:*:*:*:rust:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-29x4-r6jv-ff4w