{"id":"CVE-2026-104419","summary":"Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes","details":"Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.","aliases":["GHSA-qhr3-cvch-5fh2"],"modified":"2026-10-04T02:46:34.805452046Z","published":"2026-10-02T11:38:01.103Z","database_specific":{"cwe_ids":["CWE-345"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104419.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104419.json"},{"type":"ADVISORY","url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-qhr3-cvch-5fh2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104419"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/zebra-before-6.3.0-honest-peer-banning-via-far-ahead-findblocks-hashes"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zcashfoundation/zebra","events":[{"introduced":"1440b43ca7df59aca948090d45117557b217a6cd"},{"fixed":"f5c5277fe41eba9c74f37098738f93f35dd70d60"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.3.0"},{"introduced":"4.5.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["zebra-utils-v10.0.0","zebra-state-v12.0.1","zebra-script-v10.1.2","zebra-rpc-v15.0.0","zebra-node-services-v9.1.2","zebra-network-v11.0.0","zebra-consensus-v14.0.1","zebra-chain-v11.3.0","v6.2.3","zebra-utils-v9.1.4","zebra-state-v12.0.0","zebra-rpc-v14.0.0","zebra-network-v10.2.1","zebra-consensus-v14.0.0","v6.2.2","zebra-utils-v9.1.3","zebra-state-v11.1.1","zebra-rpc-v13.0.0","zebra-consensus-v13.0.0","v6.2.1","zebra-state-v11.1.0","zebra-network-v10.2.0","zebra-consensus-v12.0.1","v6.2.0","zebra-utils-v9.1.1","zebra-state-v11.0.0","zebra-script-v10.1.1","zebra-rpc-v12.0.0","zebra-node-services-v9.1.1","zebra-network-v10.1.1","zebra-consensus-v12.0.0","zebra-chain-v11.2.0","v6.1.0","tower-fallback-v0.2.43","tower-batch-control-v1.1.1","zebra-utils-v9.1.0","zebra-state-v10.1.0","zebra-script-v10.1.0","zebra-rpc-v11.1.0","zebra-node-services-v9.1.0","zebra-network-v10.1.0","zebra-consensus-v11.0.0","zebra-chain-v11.1.0","v6.0.0","tower-fallback-v0.2.42","tower-batch-control-v1.1.0","v6.0.0-rc.0","v5.2.0","v5.1.0","v5.1.1","v5.0.0","v4.5.1","v4.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104419.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}]}