CVE-2026-104428: Zcashfoundation Zebra
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.
Affected products
- Zcashfoundation Zebra: before 11.0.0 (fixed in 11.0.0)
Published 2026-10-02. Last modified 2026-10-06.