CVE-2026-104425
ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.
- Published Oct 2, 2026
- CVSS 6.9 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available