CVE-2026-104419

Source
https://cve.org/CVERecord?id=CVE-2026-104419
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104419.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104419
Aliases
  • GHSA-qhr3-cvch-5fh2
Published
2026-10-02T11:38:01Z
Modified
2026-10-04T02:46:34Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes
Details

Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-345"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104419.json"
}
References

Affected packages

Git / github.com/zcashfoundation/zebra

Affected ranges

Type
GIT
Repo
https://github.com/zcashfoundation/zebra
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "6.3.0"
        },
        {
            "introduced":  "4.5.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

tower-batch-control-v1.*
tower-batch-control-v1.1.0
tower-batch-control-v1.1.1
tower-fallback-v0.*
tower-fallback-v0.2.42
tower-fallback-v0.2.43
v4.*
v4.5.0
v4.5.1
v5.*
v5.0.0
v5.1.0
v5.1.1
v5.2.0
v6.*
v6.0.0
v6.0.0-rc.0
v6.1.0
v6.2.0
v6.2.1
v6.2.2
v6.2.3
zebra-chain-v11.*
zebra-chain-v11.1.0
zebra-chain-v11.2.0
zebra-chain-v11.3.0
zebra-consensus-v11.*
zebra-consensus-v11.0.0
zebra-consensus-v12.*
zebra-consensus-v12.0.0
zebra-consensus-v12.0.1
zebra-consensus-v13.*
zebra-consensus-v13.0.0
zebra-consensus-v14.*
zebra-consensus-v14.0.0
zebra-consensus-v14.0.1
zebra-network-v10.*
zebra-network-v10.1.0
zebra-network-v10.1.1
zebra-network-v10.2.0
zebra-network-v10.2.1
zebra-network-v11.*
zebra-network-v11.0.0
zebra-node-services-v9.*
zebra-node-services-v9.1.0
zebra-node-services-v9.1.1
zebra-node-services-v9.1.2
zebra-rpc-v11.*
zebra-rpc-v11.1.0
zebra-rpc-v12.*
zebra-rpc-v12.0.0
zebra-rpc-v13.*
zebra-rpc-v13.0.0
zebra-rpc-v14.*
zebra-rpc-v14.0.0
zebra-rpc-v15.*
zebra-rpc-v15.0.0
zebra-script-v10.*
zebra-script-v10.1.0
zebra-script-v10.1.1
zebra-script-v10.1.2
zebra-state-v10.*
zebra-state-v10.1.0
zebra-state-v11.*
zebra-state-v11.0.0
zebra-state-v11.1.0
zebra-state-v11.1.1
zebra-state-v12.*
zebra-state-v12.0.0
zebra-state-v12.0.1
zebra-utils-v10.*
zebra-utils-v10.0.0
zebra-utils-v9.*
zebra-utils-v9.1.0
zebra-utils-v9.1.1
zebra-utils-v9.1.3
zebra-utils-v9.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104419.json"