CVE-2026-104420: Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks

Published Oct 2, 2026
·
Updated

Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.

Affected Software

1 affected component
Zcash Foundation Zebra<6.3.0

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Zcash Foundation Zebra deployments running a version before 6.3.0 are affected. The issue is reachable through inbound peers supplying gossiped blocks.

2

Does exploitation require authentication or prior access?

No. The listed attack vector is network-based with no privileges or user interaction required, and the description identifies unauthenticated peers as the attackers.

3

What can an attacker do in practice?

An attacker can repeatedly submit invalid gossiped blocks without accumulating the misbehavior score that would normally lead to a ban. This can repeatedly trigger block download and Equihash verification work, causing an availability impact.

4

How can I determine whether my node may already be affected?

Check whether the Zebra version is earlier than 6.3.0 and whether the node accepts inbound peer connections. The provided information does not specify a log indicator or other forensic artifact for confirmed exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203