CVE-2026-104428: Zcashfoundation Zebra

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.

Affected products

Published 2026-10-02. Last modified 2026-10-06.