CVE-2026-104419: Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes
Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.
Affected Software
Event History
Frequently Asked Questions
Which nodes are exposed to this issue?
Syncing zebrad nodes running versions 4.5.0 before 6.3.0 are exposed. The impact is the loss of honest peers from the node’s peer set, which can increase eclipse risk.
What does an attacker need to do to exploit it?
A remote peer must return real block hashes in a FindBlocks response that are more than 50,000 heights ahead of the syncing node’s tip. No authentication, user interaction, or prior privileges are required.
Why are honest peers banned instead of the malicious peer?
The affected versions discard the identity of the peer that supplied FindBlocks hashes. When a requested block is served far ahead of the tip, zebrad assigns 100 misbehavior points—the ban threshold—to the peer serving that block rather than reliably attributing the behavior to the hash-supplying peer.
What is the available remediation?
Upgrade zebrad to version 6.3.0 or later. The affected version range begins at 4.5.0 and ends before 6.3.0.