CVE-2026-44499

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems — all exercisable from a single TCP connection — to create a monotonically growing block deficit that never self-heals. This issue has been patched in version 4.4.0.
CVSS

No CVSS.

Configurations

No configuration.

History

08 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 16:16

Updated : 2026-05-12 16:45


NVD link : CVE-2026-44499

Mitre link : CVE-2026-44499

CVE.ORG link : CVE-2026-44499


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling