CVE-2026-104432: Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response
Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtaintips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Zcash Foundation Zebra versions before 6.3.0 are affected. The issue specifically affects nodes relying on the /ready endpoint to determine whether they are close to the chain tip.
What does an attacker need to do to trigger the false-ready state?
A peer needs to return only the next block hash in response to a FindBlocks request. Zebra then discards that valid one-hash response, produces a zero-length synchronization sample, and can report readiness while still behind the tip.
What is the operational impact of exploitation?
The node's /ready endpoint can return HTTP 200 OK even though the node has not synchronized to the chain tip. The provided severity vector indicates an availability impact and no stated confidentiality or integrity impact.