Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-104436

LOW NVD
CVSS Score 3.7
Severity LOW
Published Oct 02, 2026
Vendor unknown

Description

Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.

References