zebrad is vulnerable to Denial of Service (DoS)
59
Medium Risk
When a block fails contextual verification Zebra records its hash in an in-memory map and propagates that failure to any child whose parent is in the map. The entry is only removed by a fixed-size limit or a restart, never when the canonical block at that hash later commits successfully. A peer can get a poisoned block sharing a canonical block's header hash rejected first, so the stale entry then blocks the canonical successor and stalls the node at that height. The fix removes the hash from the map when the canonical block at that hash commits.
You are affected if you are using a version that falls within the vulnerable range and your node accepts inbound peer-to-peer connections.
zebrad is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 6.0.0.
Upgrade the zebrad library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant