Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zcashfoundation
Zcashfoundation zebra |
|
| Vendors & Products |
Zcashfoundation
Zcashfoundation zebra |
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance. | |
| Title | Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length | |
| First Time appeared |
Zfnd
Zfnd zebra |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zfnd
Zfnd zebra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T14:51:28.130Z
Reserved: 2026-10-02T00:50:26.604Z
Link: CVE-2026-104436
Updated: 2026-10-02T14:51:25.345Z
Status : Received
Published: 2026-10-02T12:17:14.210
Modified: 2026-10-02T15:17:06.770
Link: CVE-2026-104436
No data.
OpenCVE Enrichment
Updated: 2026-10-02T13:00:13Z