Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-104419

Опубликовано: 02 окт. 2026
Источник: nvd
CVSS3: 4.8
EPSS Низкий

Описание

Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.

EPSS

Процентиль: 2%
0.00126
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 4.8
github
3 дня назад

Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.

EPSS

Процентиль: 2%
0.00126
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-345