CVE-2026-104426: Inefficient Algorithmic Complexity in ZcashFoundation zebra
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds.
AI Analysis
Technical Summary
CVE-2026-104426 affects Zebra prior to version 6.1.0. The vulnerability arises from an inefficient algorithmic complexity in the remaining_transaction_value function, which clones the entire block-level spent-UTXO map for each transaction during contextual verification. This inefficiency can be exploited by attackers who create a large number of minimal single-input transactions (around 26,000) in a single block, resulting in a denial-of-service condition by stalling every validating node for more than 52 seconds.
Potential Impact
The vulnerability can cause a denial-of-service condition on Zebra validating nodes by significantly delaying transaction verification. This can stall nodes for over 52 seconds when processing a block containing a large number of minimal single-input transactions, potentially disrupting normal blockchain validation and network operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability affects Zebra versions before 6.1.0, upgrading to version 6.1.0 or later is implied as a remediation step once confirmed by the vendor. Until an official fix is available, operators should monitor vendor communications for patches or temporary mitigations.
CVE-2026-104426: Inefficient Algorithmic Complexity in ZcashFoundation zebra
Description
Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds.
CVSS v4.0
Score 8.2high
Affected software
ZcashFoundation
zebra
pkg:github/zcashfoundation/zebraRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104426 affects Zebra prior to version 6.1.0. The vulnerability arises from an inefficient algorithmic complexity in the remaining_transaction_value function, which clones the entire block-level spent-UTXO map for each transaction during contextual verification. This inefficiency can be exploited by attackers who create a large number of minimal single-input transactions (around 26,000) in a single block, resulting in a denial-of-service condition by stalling every validating node for more than 52 seconds.
Potential Impact
The vulnerability can cause a denial-of-service condition on Zebra validating nodes by significantly delaying transaction verification. This can stall nodes for over 52 seconds when processing a block containing a large number of minimal single-input transactions, potentially disrupting normal blockchain validation and network operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability affects Zebra versions before 6.1.0, upgrading to version 6.1.0 or later is implied as a remediation step once confirmed by the vendor. Until an official fix is available, operators should monitor vendor communications for patches or temporary mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-02T00:46:23.830Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abf99afa43b0b3b89b26905
Added to database: 10/02/2026, 11:46:55 UTC
Last enriched: 10/02/2026, 12:02:36 UTC
Last updated: 10/03/2026, 03:05:01 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.