CVE-2026-104432: Zcashfoundation Zebra
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.
Affected products
- Zcashfoundation Zebra: before 6.3.0 (fixed in 6.3.0)
Published 2026-10-02. Last modified 2026-10-06.