zebrad is vulnerable to Denial of Service (DoS)
53
Medium Risk
Zebra enforces a per-peer cap on concurrent inbound mempool admissions, but the cap applies only when a candidate transaction carries its sending peer as the source. Transactions received as direct peer-to-peer messages are converted to internal push requests without preserving the peer address, so they enter the queue with no source and bypass the per-peer cap. A single inbound peer can then occupy more than its intended share of admission capacity and crowd out honest peers' transaction relay. The fix preserves the peer address for directly pushed transactions so they are counted against that peer's per-peer budget.
You are affected if you are using a version that falls within the vulnerable range and your node accepts inbound peer-to-peer connections and is near the chain tip.
zebrad is vulnerable to Denial of Service (DoS) in versions 5.0.0 - 5.2.0.
Upgrade the zebrad library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant