CVE-2026-104422: Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite
The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Zebra zebrad versions before 6.3.0 are affected during block-sync downloads.
What does an attacker need to exploit this issue?
The attacker needs to act as a malicious supplying peer and repeatedly provide a canonical block with a rewritten coinbase scriptSig that claims height 1. No authentication or user interaction is indicated by the supplied severity vector.
Why can the altered block still match the requested block hash?
For V5 transactions, transaction IDs exclude the coinbase scriptSig. This allows the peer to retain the requested hash while changing the apparent coinbase height.
What is the practical impact on a node?
The malicious peer can cause the node to drop the supplied block before consensus validation and avoid peer penalization. Repeating this can delay the node's discovery of the newest block during synchronization.