๐Ÿ” CVE Alert

CVE-2026-44499

UNKNOWN 0.0

ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems โ€” all exercisable from a single TCP connection โ€” to create a monotonically growing block deficit that never self-heals. This issue has been patched in version 4.4.0.

CWE CWE-770
Vendor zcashfoundation
Product zebra
Published May 8, 2026
Last Updated May 8, 2026
Stay Ahead of the Next One

Get instant alerts for zcashfoundation zebra

Be the first to know when new unknown vulnerabilities affecting zcashfoundation zebra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ZcashFoundation / zebra
< 4.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-h9hm-m2xj-4rq9