Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
Low0xCERT-2026-0200·

zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length

zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length. You are affected if: 1. You run zebrad up to and including v4.4.1. 2. Your node accepts inbound P2P connections. The readgetblocks and readgetheaders codec paths accepted block locator vectors up to approximately 65,535 entries (the generic TrustedPreallocate ceiling derived from MAXPROTOCOLMESSAGELEN), rather than the protocol-specification limit of 101 entries (matching zcashd's MAXLOCATORSZ).

Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below

Summary

You are affected if: 1. You run zebrad up to and including v4.4.1. 2. Your node accepts inbound P2P connections. The readgetblocks and readgetheaders codec paths accepted block locator vectors up to approximately 65,535 entries (the generic TrustedPreallocate ceiling derived from MAXPROTOCOLMESSAGELEN), rather than the protocol-specification limit of 101 entries (matching zcashd's MAXLOCATORSZ).

Affected

  • zebrad (rust) < 4.5.0 — fixed in 4.5.0
  • zebra-chain (rust) < 8.0.0 — fixed in 8.0.0

Severity

Low, as rated by the upstream advisory.

Recommended actions

  • Upgrade zebrad to 4.5.0 or later
  • Upgrade zebra-chain to 8.0.0 or later

Source & attribution

This 0xCERT advisory summarises GHSA-443g-gwgp-49x4 from the GitHub Advisory Database, credited upstream to dingledropper, mpguerra, oxarbitrage: https://github.com/advisories/GHSA-443g-gwgp-49x4. Details may change; refer to the original source for the authoritative record.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-07-02 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0200/signed.txt | gpg --verify