High severity7.5NVD Advisory· Published Oct 2, 2026
CVE-2026-104423
CVE-2026-104423
Description
Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.
Affected products
2- Range: <6.2.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.