CVE-2026-104423 HIGH

CVE-2026-104423: Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification

Vendor Zcashfoundation
Product zebra
Weakness CWE-405
Published October 2, 2026
Last update October 2, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.

Key dates

02Disclosure timeline

October 2, 2026 CVE published
October 2, 2026 Record updated