zebrad is vulnerable to Denial of Service (DoS)
53
Medium Risk
When Zebra sends a semantically verified block to the write task it records the block hash in an in-memory sent-hash set to avoid queueing it twice. If contextual verification rejects the block the hash was drained on the commit path but not on the block-known lookup path, so a stale rejected entry made that lookup report an honest block as already present. A peer can get a poisoned block sharing a canonical block's header hash rejected, after which the node skips downloading the honest body and lags one block behind the tip until unrelated activity or a restart clears the entry. The fix drains pending rejected hashes before the block-known lookup checks the set.
You are affected if you are using a version that falls within the vulnerable range and your node accepts inbound peer-to-peer connections.
zebrad is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 6.2.0.
Upgrade the zebrad library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant