Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zcashfoundation
Zcashfoundation zebra |
|
| Vendors & Products |
Zcashfoundation
Zcashfoundation zebra |
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline. | |
| Title | Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC | |
| First Time appeared |
Zfnd
Zfnd zebra |
|
| Weaknesses | CWE-617 | |
| CPEs | cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zfnd
Zfnd zebra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T15:30:07.619Z
Reserved: 2026-10-02T00:50:26.604Z
Link: CVE-2026-104434
Updated: 2026-10-02T15:29:46.637Z
Status : Received
Published: 2026-10-02T12:17:13.917
Modified: 2026-10-02T16:16:45.873
Link: CVE-2026-104434
No data.
OpenCVE Enrichment
Updated: 2026-10-02T13:30:05Z