CVE-2026-104424: Zcashfoundation Zebra
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.
Affected products
- Zcashfoundation Zebra: before 6.1.0 (fixed in 6.1.0)
Published 2026-10-02. Last modified 2026-10-06.