CVE-2026-104428

⚪ Do wiadomości

Błąd w metodzie getblock w zebra-rpc powoduje awarię w pętli przy wywołaniu przez atakujących.

CVSS
5.3
EPSS
0.4%
Exploit
none
Vendor
Opis źródłowy (NVD)

The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-10-02 12:17:13 UTC
Ostatnia modyfikacja (NVD)2026-10-02 17:59:09 UTC
Referencje