CVE-2026-104420: Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks
Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Zcash Foundation Zebra deployments running a version before 6.3.0 are affected. The issue is reachable through inbound peers supplying gossiped blocks.
Does exploitation require authentication or prior access?
No. The listed attack vector is network-based with no privileges or user interaction required, and the description identifies unauthenticated peers as the attackers.
What can an attacker do in practice?
An attacker can repeatedly submit invalid gossiped blocks without accumulating the misbehavior score that would normally lead to a ban. This can repeatedly trigger block download and Equihash verification work, causing an availability impact.
How can I determine whether my node may already be affected?
Check whether the Zebra version is earlier than 6.3.0 and whether the node accepts inbound peer connections. The provided information does not specify a log indicator or other forensic artifact for confirmed exploitation.