---
id: CVE-2026-104420
title: >-
  Zebra before 6.3.0 contains a protection mechanism failure that allows
  unauthenticated peers to evade misbehavior scoring by supplying invalid
  gossiped blocks
summary: >-
  Zebra before 6.3.0 contains a protection mechanism failure that allows
  unauthenticated peers to evade misbehavior scoring by supplying invalid
  gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to
  VerifyBlockError an…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-704
vendor: ZcashFoundation
product: zebra
affected:
  - zebra < 6.3.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:11.997'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104420'
references:
  - url: >-
      https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8hh2-hrf2-cqf4
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/zebra-before-6.3.0-peer-misbehavior-ban-bypass-via-gossiped-blocks
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.329Z'
---

## Overview

Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
