在 Zebra 6.3.0 之前的版本中, 存在一个不当的异常条件检查逻辑,该逻辑会丢弃有效的仅包含单个哈希值的 响应,并错误地将节点状态报告为“接近最新分叉”(close-to-tip)。当对等节点仅返回下一个区块的哈希值时,会导致同步样本长度为零,从而使 端点返回 状态,而实际上节点仍处于落后于最新区块(tip)的状态。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZcashFoundation | zebra | < 6.3.0 |
affected |
6.3.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZcashFoundation | zebra | 0 ~ 6.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104422 | 7.5 HIGH | Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite |
| CVE-2026-104431 | 7.5 HIGH | Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification |
| CVE-2026-104430 | 7.5 HIGH | Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount |
| CVE-2026-104423 | 7.5 HIGH | Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification |
| CVE-2026-104437 | 7.4 HIGH | Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling |
| CVE-2026-104435 | 7.4 HIGH | Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output |
| CVE-2026-104434 | 6.5 MEDIUM | Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC |
| CVE-2026-104426 | 5.9 MEDIUM | Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check |
| CVE-2026-104427 | 5.9 MEDIUM | Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry |
| CVE-2026-104425 | 5.3 MEDIUM | Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions |
| CVE-2026-104420 | 5.3 MEDIUM | Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks |
| CVE-2026-104429 | 5.3 MEDIUM | Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages |
| CVE-2026-104421 | 5.3 MEDIUM | Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout |
| CVE-2026-104428 | 5.3 MEDIUM | Zebra before 11.0.0 Denial of Service via getblock Verbosity 2 |
| CVE-2026-104419 | 4.8 MEDIUM | Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes |
| CVE-2026-104436 | 3.7 LOW | Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length |
| CVE-2026-104424 | 3.7 LOW | Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate |
No comments yet