← All Advisories

CVE-2026-104422

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-104422

Key Details

CVECVE-2026-104422
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsZcashFoundation zebra
Classified asCWE-345 (Insufficient Verification of Data Authenticity)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
ZcashFoundationzebra
SubsystemsGeneral OT
SectorsMultiple

What to Know

The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block. (NVD)

What to Do

Monitor ZcashFoundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-104422
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-104422