CVE-2026-104428EPSS p30.5%
CVE-2026-104428CVE-2026-104428
Description
The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 0.39% probability of exploitation · percentile 30.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-06 |