CVE-2026-104432: Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response

Published Oct 2, 2026
·
Updated

Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtaintips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.

Affected Software

1 affected component
Zcash Foundation Zebra<6.3.0

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Zcash Foundation Zebra versions before 6.3.0 are affected. The issue specifically affects nodes relying on the /ready endpoint to determine whether they are close to the chain tip.

2

What does an attacker need to do to trigger the false-ready state?

A peer needs to return only the next block hash in response to a FindBlocks request. Zebra then discards that valid one-hash response, produces a zero-length synchronization sample, and can report readiness while still behind the tip.

3

What is the operational impact of exploitation?

The node's /ready endpoint can return HTTP 200 OK even though the node has not synchronized to the chain tip. The provided severity vector indicates an availability impact and no stated confidentiality or integrity impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203