CVE-2026-104420: Zcashfoundation Zebra
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.
Affected products
- Zcashfoundation Zebra: before 6.3.0 (fixed in 6.3.0)
Published 2026-10-02. Last modified 2026-10-06.