Vulnerability Description
Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-443g-gwgp-49x4
- https://www.vulncheck.com/advisories/zebra-before-4.5.0-cpu-amplification-via-un
FAQ
What is CVE-2026-104436?
CVE-2026-104436 is a vulnerability with a CVSS score of 3.7 (LOW). Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can s...
How severe is CVE-2026-104436?
CVE-2026-104436 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-104436?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.