OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104431

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Zebra versions prior to 6.0.0 are vulnerable to a denial of service attack, where unauthenticated users can exploit the system by submitting resource-intensive mempool transactions that bypass standard checks. This can lead to the saturation of the verifier buffer, causing the node to become unresponsive. Organizations using Zebra should prioritize upgrading to version 6.0.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104431
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.