GHSA-3whf-vgf2-9w6gMedium▾ Sunlitzaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
NonFinalizedState::handle_reorg is a recursive, unbounded async function that traverses parent blocks until it finds a common ancestor on the main chain. It has no recursion depth limit and no cycle detection. A malicious or buggy validator can serve a block whose previous_block_hash points back to itself (or forms a cycle with other blocks), causing handle_reorg to infinite-loop, consuming 100% CPU and never making sync progress. Additionally, update() contains an .expect("empty snapshot impossible") that panics if the non-finalized snapshot becomes empty after trimming finalized blocks.
Location: packages/zaino-state/src/chain_index/non_finalised_state.rs:443-489
async fn handle_reorg(
&self,
working_snapshot: &mut NonfinalizedBlockCacheSnapshot,
block: &impl Block,
) -> Result<IndexedBlock, SyncError> {
let prev_block = match working_snapshot
.get_block_by_hash_bytes_in_serialized_order(block.prev_hash_bytes_serialized_order())
.cloned()
{
Some(prev_block) => {
if !working_snapshot
.heights_to_hashes
.values()
.any(|hash| hash == prev_block.hash())
{
Box::pin(self.handle_reorg(working_snapshot, &prev_block)).await? // <-- LINE 459
} else {
prev_block
}
}
None => {
let prev_block = self
.source
.get_block(HashOrHeight::Hash(
zebra_chain::block::Hash::from_bytes_in_serialized_order(
block.prev_hash_bytes_serialized_order(),
),
))
.await
.map_err(|e| { ... })?
.ok_or(SyncError::ValidatorConnectionError(...))?;
Box::pin(self.handle_reorg(working_snapshot, &*prev_block)).await? // <-- LINE 483
}
};
let indexed_block = block.to_indexed_block(&prev_block, self).await?;
working_snapshot.add_block_new_chaintip(indexed_block.clone());
Ok(indexed_block)
}
Infinite loop via self-referencing block:
B where B.prev_hash == B.hash.handle_reorg is called with B.get_block_by_hash_bytes_in_serialized_order(B.prev_hash) finds B itself in working_snapshot.blocks.B.hash in working_snapshot.heights_to_hashes? If B is a new chaintip not yet on the main chain, no.prev_block = B (the exact same block).Box::pin future each iteration, consuming heap memory and CPU.Stack exhaustion via deep reorg:
A deep reorg of >1000 blocks would recurse >1000 times. Each async recursion creates a new Box::pin future on the heap. While this won't exhaust the native stack immediately, it will allocate unbounded heap memory and CPU time, effectively DoS-ing the sync task.
.expect("empty snapshot impossible") panic:
Location: packages/zaino-state/src/chain_index/non_finalised_state.rs:543-548
new_snapshot.remove_finalized_blocks(finalized_height);
let best_block = &new_snapshot
.blocks
.values()
.max_by_key(|block| block.chainwork())
.cloned()
.expect("empty snapshot impossible"); // <-- LINE 548
If finalized_height is greater than or equal to all blocks in new_snapshot.blocks, remove_finalized_blocks retains only blocks at or above that height. If none exist, new_snapshot.blocks becomes empty. The .expect() then panics. While the comment claims this is "impossible," defensive programming dictates it is reachable under corruption or edge-case sync conditions.
header.previous_block_hash == block.hash().NonFinalizedState::sync enters handle_reorg and infinite-loops.SyncError::ReorgFailure if exceeded:
const MAX_REORG_DEPTH: usize = 1000;
HashSet<BlockHash> during traversal to detect cycles and abort with an error..expect("empty snapshot impossible") with a proper Err(UpdateError::DatabaseHole) or similar error return.handle_reorg, starving the async runtime and stalling response serving.zaino-state < 0.4.1Upgrade to a patched release:
zaino-state 0.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak
CVE-2025-11362High· 7.5Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding
CVE-2023-5379High· 7.5A flaw was found in Undertow
CVE-2024-12254High· 7.5Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"
CVE-2022-21952High· 7.5A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS
CVE-2026-25535High· 7.5jsPDF is a library to generate PDFs in JavaScript