GHSA-3xx8-299f-8q53MediumCVSS 3.7

Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template...

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.

🔗 References (4)