CVE-2026-104431

🟡 Monitoruj

Wersja Zebra przed 6.0.0 ma lukę, która pozwala na zdalne zablokowanie węzła.

CVSS
7.5
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-10-02 12:17:13 UTC
Ostatnia modyfikacja (NVD)2026-10-02 17:59:09 UTC
Referencje