MEDIUM 6.9 NVD
CVE-2026-104421
Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashe
Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.
References
- https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-x93j-mj2f-q338
- https://www.vulncheck.com/advisories/zebra-before-6.2.1-block-download-denial-of-service-v
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-10-02 via NVD.
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.