Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
Medium0xCERT-2026-0192·

Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers

Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers. Several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced.

Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below

Summary

Several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced.

Affected

  • zebra-network (rust) <= 5.0.2 — fixed in 6.0.0
  • zebrad (rust) < 4.4.0 — fixed in 4.4.0
  • zebra-chain (rust) <= 6.0.3 — fixed in 7.0.0

Severity

Medium, as rated by the upstream advisory.

Recommended actions

  • Upgrade zebra-network to 6.0.0 or later
  • Upgrade zebrad to 4.4.0 or later
  • Upgrade zebra-chain to 7.0.0 or later

Source & attribution

This 0xCERT advisory summarises GHSA-438q-jx8f-cccv / CVE-2026-44500 from the GitHub Advisory Database, credited upstream to Zk-nd3r: https://github.com/advisories/GHSA-438q-jx8f-cccv. Details may change; refer to the original source for the authoritative record.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-05-07 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0192/signed.txt | gpg --verify