Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 02 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zcashfoundation
Zcashfoundation zebra |
|
| Vendors & Products |
Zcashfoundation
Zcashfoundation zebra |
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive. | |
| Title | Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification | |
| First Time appeared |
Zfnd
Zfnd zebra |
|
| Weaknesses | CWE-405 | |
| CPEs | cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zfnd
Zfnd zebra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T14:53:54.651Z
Reserved: 2026-10-02T00:50:26.603Z
Link: CVE-2026-104431
Updated: 2026-10-02T14:53:50.963Z
Status : Received
Published: 2026-10-02T12:17:13.610
Modified: 2026-10-02T15:17:06.643
Link: CVE-2026-104431
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:15:14Z