zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length. You are affected if: 1. You run zebrad up to and including v4.4.1. 2. Your node accepts inbound P2P connections. The readgetblocks and readgetheaders codec paths accepted block locator vectors up to approximately 65,535 entries (the generic TrustedPreallocate ceiling derived from MAXPROTOCOLMESSAGELEN), rather than the protocol-specification limit of 101 entries (matching zcashd's MAXLOCATORSZ).
Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below
Summary
You are affected if: 1. You run zebrad up to and including v4.4.1. 2. Your node accepts inbound P2P connections. The readgetblocks and readgetheaders codec paths accepted block locator vectors up to approximately 65,535 entries (the generic TrustedPreallocate ceiling derived from MAXPROTOCOLMESSAGELEN), rather than the protocol-specification limit of 101 entries (matching zcashd's MAXLOCATORSZ).
Affected
- zebrad (rust) < 4.5.0 — fixed in 4.5.0
- zebra-chain (rust) < 8.0.0 — fixed in 8.0.0
Severity
Low, as rated by the upstream advisory.
Recommended actions
- Upgrade zebrad to 4.5.0 or later
- Upgrade zebra-chain to 8.0.0 or later
Source & attribution
This 0xCERT advisory summarises GHSA-443g-gwgp-49x4 from the GitHub Advisory Database, credited upstream to dingledropper, mpguerra, oxarbitrage: https://github.com/advisories/GHSA-443g-gwgp-49x4. Details may change; refer to the original source for the authoritative record.
References
OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.
Published 2026-07-02 · last updated 2026-10-08
curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0200/signed.txt | gpg --verify