The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block. | |
| Title | Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite | |
| First Time appeared |
Zfnd
Zfnd zebra |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zfnd
Zfnd zebra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T11:38:03.646Z
Reserved: 2026-10-02T00:46:23.830Z
Link: CVE-2026-104422
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses