CVE-2026-104432: Improper Check for Unusual or Exceptional Conditions in ZcashFoundation zebra
Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.
AI Analysis
Technical Summary
CVE-2026-104432 affects Zebra prior to version 6.3.0. The vulnerability is an improper exceptional condition check in the ChainSync::obtain_tips function. This causes valid one-hash FindBlocks responses to be discarded, leading to false reporting of close-to-tip status. Specifically, when peers return only the next block hash, the sync sample length is zero, causing the /ready endpoint to incorrectly indicate the node is synchronized (HTTP 200 OK) while it is actually behind the blockchain tip.
Potential Impact
The vulnerability causes Zebra nodes to falsely report synchronization status, potentially misleading monitoring systems or operators into believing the node is up to date when it is not. This could affect the reliability of node status reporting but does not directly indicate a compromise or data loss. There are no known exploits in the wild.
Mitigation Recommendations
A fix is available in Zebra version 6.3.0. Users should upgrade to version 6.3.0 or later to remediate this issue. No other mitigation steps are indicated.
CVE-2026-104432: Improper Check for Unusual or Exceptional Conditions in ZcashFoundation zebra
Description
Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.
CVSS v4.0
Score 6.9medium
Affected software
ZcashFoundation
zebra
pkg:github/zcashfoundation/zebraRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-104432 affects Zebra prior to version 6.3.0. The vulnerability is an improper exceptional condition check in the ChainSync::obtain_tips function. This causes valid one-hash FindBlocks responses to be discarded, leading to false reporting of close-to-tip status. Specifically, when peers return only the next block hash, the sync sample length is zero, causing the /ready endpoint to incorrectly indicate the node is synchronized (HTTP 200 OK) while it is actually behind the blockchain tip.
Potential Impact
The vulnerability causes Zebra nodes to falsely report synchronization status, potentially misleading monitoring systems or operators into believing the node is up to date when it is not. This could affect the reliability of node status reporting but does not directly indicate a compromise or data loss. There are no known exploits in the wild.
Mitigation Recommendations
A fix is available in Zebra version 6.3.0. Users should upgrade to version 6.3.0 or later to remediate this issue. No other mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-02T00:50:26.603Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abf99b0a43b0b3b89b26946
Added to database: 10/02/2026, 11:46:56 UTC
Last enriched: 10/02/2026, 12:02:11 UTC
Last updated: 10/03/2026, 03:07:31 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.