Medium severity5.3NVD Advisory· Published Oct 2, 2026
CVE-2026-104420
CVE-2026-104420
Description
Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.
Affected products
1- Range: <6.3.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.