CVE-2026-104421: Zcashfoundation Zebra
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.
Affected products
- Zcashfoundation Zebra: before 6.2.1 (fixed in 6.2.1)
Published 2026-10-02. Last modified 2026-10-02.