zebrad is vulnerable to Denial of Service (DoS)
53
Medium Risk
When a directly pushed mempool transaction fails verification Zebra does not record the sending peer's address, so that peer is never misbehavior-scored or banned. Because Orchard proof verification runs through a process-global batch verifier shared by mempool and block verification, one invalid proof forces the whole batch onto the slow per-proof path, including honest block proofs batched with it. A peer can repeatedly push transactions carrying invalid proofs at no cost and sustain degraded block-processing performance. The fix attributes pushed-transaction verification failures to the sending peer so existing misbehavior scoring can ban it.
You are affected if you are using a version that falls within the vulnerable range and your node accepts inbound peer-to-peer connections.
zebrad is vulnerable to Denial of Service (DoS) in versions 6.0.0 - 6.0.0.
Upgrade the zebrad library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant