CVE-2026-104436
LOW
NVD
CVSS Score
3.7
Severity
LOW
Published
Oct 02, 2026
Vendor
unknown
Description
Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.