Medium severity5.3NVD Advisory· Published Oct 2, 2026· Updated Oct 2, 2026
CVE-2026-104429
CVE-2026-104429
Description
Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.
Affected products
2- Range: <6.0.0-rc.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.