CVE-2026-44499
ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems โ all exercisable from a single TCP connection โ to create a monotonically growing block deficit that never self-heals. This issue has been patched in version 4.4.0.
| CWE | CWE-770 |
| Vendor | zcashfoundation |
| Product | zebra |
| Published | May 8, 2026 |
| Last Updated | May 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for zcashfoundation zebra
Be the first to know when new unknown vulnerabilities affecting zcashfoundation zebra are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ZcashFoundation / zebra
< 4.4.0