Improper control of a resource through its lifetime in Zcash - #VU130978
Published: May 11, 2026
Zcash
Electric Coin Co.
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in zcashd block ingestion when processing a poisoned NU5+ block body before the canonical body. A remote attacker can send a specially crafted block body with mutated V5 transaction authorizing data to cause a denial of service.
Successful exploitation requires winning a P2P delivery race for a newly mined NU5+ block, and the targeted node can remain stalled on a stale chain tip until manual recovery.