CVE-2026-104425: Zcashfoundation Zebra

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.

Affected products

Published 2026-10-02. Last modified 2026-10-02.