CVE-2026-104426: Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remainingtransactionvalue that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Zcash Foundation Zebra versions before 6.1.0 are affected. Every validating node processing a crafted block is susceptible to the verification stall.
What must an attacker do to trigger the denial of service?
An attacker needs to get roughly 26,000 minimal single-input transactions into one block, either by mining the block or by seeding the mempool. No privileges or user interaction are required.
What is the expected operational impact?
Processing the crafted block can stall each validating node for more than 52 seconds. The issue affects availability; no confidentiality or integrity impact is stated.