Medium severity5.9NVD Advisory· Published Oct 2, 2026
CVE-2026-104427
CVE-2026-104427
Description
Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.1.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.