CVE-2026-104419
⚪ Do wiadomości
Błąd w Zebra pozwala na banowanie uczciwych węzłów przez złośliwe peer, zwiększając ryzyko eklipsy.
CVSS
4.8
EPSS
0.1%
Exploit
none
Vendor
Opis źródłowy (NVD)
Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-10-02 12:17:11 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-02 17:59:09 UTC |