Feed/GHSA-3whf-vgf2-9w6g
GHSA-3whf-vgf2-9w6gMEDIUMCVSS 0.0

zaino-state has a Non-Finalized State Reorg — No Cycle Detection or Depth Limit

Published Jul 31, 2026·Updated Jul 31, 2026

NVD Description

### Summary `NonFinalizedState::handle_reorg` is a recursive, unbounded async function that traverses parent blocks until it finds a common ancestor on the main chain. It has **no recursion depth limit** and **no cycle detection**. A malicious or buggy validator can serve a block whose `previous_block_hash` points back to itself (or forms a cycle with other blocks), causing `handle_reorg` to infinite-loop, consuming 100% CPU and never making sync progress. Additionally, `update()` contains an `.expect("empty snapshot impossible")` that panics if the non-finalized snapshot becomes empty after trimming finalized blocks. ### Details **Location:** `packages/zaino-state/src/chain_index/non_finalised_state.rs:443-489` ```rust async fn handle_reorg( &self, working_snapshot: &mut NonfinalizedBlockCacheSnapshot, block: &impl Block, ) -> Result<IndexedBlock, SyncError> { let prev_block = match working_snapshot .get_block_by_hash_bytes_in_serialized_order(block.prev_hash_bytes_serialized_order()) .cloned() { Some(prev_block) => { if !working_snapshot .heights_to_hashes .values() .any(|hash| hash == prev_block.hash()) { Box::pin(self.handle_reorg(working_snapshot, &prev_block)).await? // <-- LINE 459 } else { prev_block } } None => { let prev_block = self .source .get_block(HashOrHeight::Hash( zebra_chain::block::Hash::from_bytes_in_serialized_order( block.prev_hash_bytes_serialized_order(), ), )) .await .map_err(|e| { ... })? .ok_or(SyncError::ValidatorConnectionError(...))?; Box::pin(self.handle_reorg(working_snapshot, &*prev_block)).await? // <-- LINE 483 } }; let indexed_block = block.to_indexed_block(&prev_block, self).await?; working_snapshot.add_block_new_chaintip(indexed_block.clone()); Ok(indexed_block) } ``` **Infinite loop via self-referencing block:** 1. A compromised validator serves a block `B` where `B.prev_hash == B.hash`. 2. `handle_reorg` is called with `B`. 3. `get_block_by_hash_bytes_in_serialized_order(B.prev_hash)` finds `B` itself in `working_snapshot.blocks`. 4. Check: is `B.hash` in `working_snapshot.heights_to_hashes`? If `B` is a new chaintip not yet on the main chain, **no**. 5. Recurse with `prev_block` = `B` (the exact same block). 6. This repeats forever. The async recursion builds a new `Box::pin` future each iteration, consuming heap memory and CPU. **Stack exhaustion via deep reorg:** A deep reorg of >1000 blocks would recurse >1000 times. Each async recursion creates a new `Box::pin` future on the heap. While this won't exhaust the native stack immediately, it will allocate unbounded heap memory and CPU time, effectively DoS-ing the sync task. **`.expect("empty snapshot impossible")` panic:** **Location:** `packages/zaino-state/src/chain_index/non_finalised_state.rs:543-548` ```rust new_snapshot.remove_finalized_blocks(finalized_height); let best_block = &new_snapshot .blocks .values() .max_by_key(|block| block.chainwork()) .cloned() .expect("empty snapshot impossible"); // <-- LINE 548 ``` If `finalized_height` is greater than or equal to all blocks in `new_snapshot.blocks`, `remove_finalized_blocks` retains only blocks at or above that height. If none exist, `new_snapshot.blocks` becomes empty. The `.expect()` then panics. While the comment claims this is "impossible," defensive programming dictates it is reachable under corruption or edge-case sync conditions. ### PoC 1. Run a regtest. 2. Serve a block where `header.previous_block_hash == block.hash()`. 3. Zaino's `NonFinalizedState::sync` enters `handle_reorg` and infinite-loops. 4. Sync never completes. CPU usage pegs to 100%. No new blocks are served to clients. ### Fix 1. **Add an explicit recursion depth limit** (e.g., max 1000 iterations) and return `SyncError::ReorgFailure` if exceeded: ```rust const MAX_REORG_DEPTH: usize = 1000; ``` 2. **Track visited hashes** in a `HashSet<BlockHash>` during traversal to detect cycles and abort with an error. 3. **Replace `.expect("empty snapshot impossible")`** with a proper `Err(UpdateError::DatabaseHole)` or similar error return. ### Additional Attack Vectors - **Deep reorg DoS:** A miner with significant hash power (or a compromised validator) triggers a deep reorg. Zaino spends excessive CPU and memory in `handle_reorg`, starving the async runtime and stalling response serving. - **Fork-choice manipulation:** By serving cyclic or very deep sidechains, an attacker can keep Zaino stuck in reorg handling indefinitely, preventing it from ever serving the real best chain.

Affected Packages (1)

zaino-stateCARGO
Fixed in 0.4.1

Public Exploits & PoCs110 found

PoC: YellowKey-BitLocker-CVE-2026-45585

YellowKey BitLocker recovery - bitlocker yellowkey, yellowkey bitlocker, CVE-2026-45585, yellowkey github, yellowkey vulnerability, yellowkey CVE, TPM, BitLocker recovery key backup, Windows 10/11, CLI GUI, portable audit tool. Download:🡇

13

PoC: Keycloak_CVE-2026-18963_PoC

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

12

PoC: CVE-2026-18963-keycloak

CVE-2026-18963

11

PoC: pixel-ksu-root

adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.

5

[POC] GHSA-3whf-vgf2-9w6g — CVE-2024-36104-PoC

PoC for CVE-2024-36104 — unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path traversal to ProgramExport

3

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723

A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.

2

[POC] GHSA-3whf-vgf2-9w6g — QuestStack

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

2

PoC: CVE-2026-43914-PoC

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

2

[POC] GHSA-3whf-vgf2-9w6g — CVE-2023-44487-HTTP2-DoS-Rapid-Reset-Exploit

Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control, stealth mode with randomized headers, real-time metrics, and risk assessment reporting. For authorized penetration testing only. By Sudeepa Wanigarathna

1

[POC] GHSA-3whf-vgf2-9w6g — cicd-goat-vapt-writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.

1

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723

Fastjson RCE

1

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-16723

This is N-day patch we releasing by testing our model capabilities

1

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-54121-CertiGhost

CVE-2026-54121(CertiGhost) without MachineAccountQuota POC

1

[POC] GHSA-3whf-vgf2-9w6g — CVE-2026-60004

Gitea diffpatch RCE

1

[POC] GHSA-3whf-vgf2-9w6g — Sharepoint-cve-2023-29375-incident-response

End-to-end SOC incident analysis and threat hunting playbook targeting Microsoft SharePoint privilege escalation (CVE-2023-29375) using SIEM logs, firewall data, and threat intel.

1

PoC: CVE-2026-72898

Metabase SQLi

1

PoC: CVE-2026-19478

GitLab Code injection

1

PoC: CVE-2026-75604

CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing

1

PoC: CVE-2026-19632

CVE-2026-19632 - TranslatePress One-Day PoC

1

PoC: CVE-2026-56705

CVE-2026-56705 - Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection (ODBC TraceFile arbitrary file write). PoC, Docker lab and negative test included.

1

PoC: CVE-2026-75604-poc

CVE-2026-75604 Next.js Windows RCE poc

1

PoC: CVE-2026-4692-trust-me-im-in-rdm

Firefox BrowsingContext field-sync authz bypass (N-day, bug 2017643): forged PContent::CommitBrowsingContextTransaction sets InRDMPane=true from a compromised content process - parent applies it. Prerequisite primitive for privileged-UI touch-event injection.

1

PoC: CVE-2022-28906-POC

CVE-2022-28906 Proof of concept in Python3

1

PoC: CVE-2026-41551

ROS# 路径遍历漏洞(CVE-2026-41551)

1

PoC: cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability affecting the SSL-VPN service in certain versions of FortiOS.

1

PoC: CVE-2026-15469

CVE-2026-15469 — Hard-coded RSA-512 mesh group private key in TP-Link Deco XE75/XE5300/WE10800 (CWE-321). Advisory, analysis & PoC methodology (EN/KO).

1

PoC: CVE-2026-32475-PoC

PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.

1

PoC: CVE-2026-12295-UXXS-in-my-wasm

Firefox content->parent srcdoc forge (N-day, bug 2040160): forged PDocumentChannel with SrcdocData on a non-about:srcdoc URI -> attacker HTML served at victim origin (UXSS), via mojo-port send-path injection from a compromised content process

1

PoC: CVE-2026-74939-escape-the-mac-n-cheese-box

Firefox content-to-parent IPDL privilege escalation (N-day, bug 2054416): forged PDocumentChannel with RemoteTypeOverride -> privilegedabout process placement, via mojo-port send-path injection from a compromised content process

1

PoC: CVE-2021-27876-veritas-backup

Metasploit module: Veritas Backup Exec Agent SHA-auth NDMP remote code execution (CVE-2021-27876/27877/27878)

PoC: rmg-s9180-fzg1

Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

PoC: hacktivity-vulns-exploits-lab

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).

PoC: CVE-2026-55040-Mass-Exploit

CVE-2026-55040

PoC: Project-CVE-2026-75604

A Python-based exploitation framework for CVE-2026-75604 that enables authorized penetration testers to validate Next.js Windows cache traversal vulnerabilities. Deploys reverse shells and webshells via path traversal, with built-in target verification and proxy support for seamless integration into standard pentest workflows.

PoC: CVE-2015-3246

CVE-2015-3246

PoC: CVE-2015-5287

CVE-2015-5287

PoC: htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access, and privilege escalation through a vulnerable Gitea template synchronization service.

PoC: Cisco-CVE-2026-20303-More

CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313

PoC: CVE-Ubiquiti

CVE-2026-77542, CVE-2026-77543, CVE-2026-77545, CVE-2026-77550, CVE-2026-77551, CVE-2026-77552, CVE-2026-77553, CVE-2026-77554, CVE-2026-77557 - Draft or TODO

PoC: CVE-2026-18431

CVE-2026-18431 - Draft or TODO

PoC: CVE-2026-8467

CVE-2026-8467 - Draft or TODO

PoC: CVE-2026-50787

Security advisory for CVE-2026-50787: uncontrolled resource consumption in e-SIC Livre CAPTCHA generation leading to remote denial of service.

PoC: solarview-ics-vulnerability-analysis

Threat model and vulnerability analysis of Contec SolarView Compact (CVE-2022-29303)

PoC: CVE-2026-72898-metabase-sqli

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

PoC: By-Poloss..-..CVE-2026-18080

Poc CVE-2026-18080

PoC: CVE-2026-63520

POC pre-auth RCE on Sharepoint chain

PoC: f_hid-4.14-backports

Backports of three published f_hid fixes (incl. CVE-2026-31721, CVE-2026-31606) to an EOL Linux 4.14.190 Android vendor kernel, with on-device verification records.

PoC: chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome extension leveraging social engineering.

PoC: CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

CVE-2026-19912, CVE-2026-19913, CVE-2026-19914

PoC: CVE-2026-19632-POC

PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

PoC: ghostlock-infinix-hot70

Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.

PoC: CVE-2025-2945-pgAdmin-RCE

PoC for CVE-2025-2945 — pgAdmin 4 authenticated eval() injection RCE, CVSS 9.9

PoC: CVE-2026-63072

CVE-2026-63072

PoC: CVE-2026-76904

PostGIS SQL Injection GeoTools

PoC: CVE-2014-085

ZooKeeper 未授权访问漏洞(CVE-2014-085)PoC 及靶场

PoC: hdwebmobile-photo-video-reviews

WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction

PoC: Exploit-CVE-2026-56705

CVE-2026-56705 — Adminer < 5.4.3 Unauthenticated RCE via MSSQL PDO DSN Injection

PoC: CVE-2026-73570

Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)

PoC: vivo-root-build

vivo/iQOO 提权 so 编译(CVE-2026-43499)

PoC: CVE-2026-72530-TrueConf-Sandbox-Escape-

Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.

PoC: CVE-2021-41773-Exploit

CVE-2021-41773 Apache HTTP Server 2.4.49 Path Traversal to RCE Exploit

PoC: cve-2026-60004

CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.

PoC: CVE-2026-68820_Mass_Exploit

CVE-2026-68820 — Mass Exploit Framework Edition.

PoC: CVE-2026-58073-check

Safely detect Veeam Service Provider Console auth bypass CVE-2026-58073

PoC: CVE-2026-18963

Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.

PoC: CVE-2020-1472

CVE-2020-1472

PoC: CVE-2026-32635-Angular-XSS-Mitigation-

Demostracion educativa de mitigacion y deteccion de CVE-2026-32635: XSS en atributos i18n de Angular.

PoC: CVE-2018-16763_fuel_cms_exploit

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

PoC: CVE-2026-26211

Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.

PoC: keycloak-CVE-2026-18963

PoC, Dockerfile playground and root cause from patch diff analysis.

PoC: CVE-2026-17532-lab

CVE-2026-17532 Docker Lab.

PoC: Wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

PoC: Trespasser

CVE-2026-74970, Fission site isolation bypass in Firefox WebRender

PoC: Palimpsest

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

PoC: SkeletonKey

CVE-2026-6765, Test only FormAutofill handlers exposed in Firefox

PoC: Revenant

CVE-2026-74943, Use after free in Firefox RasterImage (sec-high)

PoC: CVE-2026-73570

PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)

PoC: EDRKiller

Use cve-2026-36425 killer edr,360 can killer

PoC: RootMyVivo

One-click root for vivo/iQOO devices on locked bootloader | CVE-2026-43499 + KernelSU

PoC: Exploit-For-CVE-2026-18963

Exploit for CVE-2026-18963 by BlackHatExploitation

PoC: CVE-2026-16348

TP-Link Archer BE800 V1 — VPN Key Injection RCE

PoC: CVE-2026-77806

CVE-2026-77806漏洞检测代码

PoC: UniBLEed

Unitree G1 RCE PoC & Scripts (CVE-2026-76639 / CVE-2026-76640) technical details at boschko.ca/g1-ble-rce/

PoC: echidna

Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327

PoC: gha-lab-227431b300

GitHub Actions workflow sandbox for CVE-2023-30628 (changelog.yml command injection)

PoC: lab-annie

Automates exploitation of CVE-2020-13160, a critical remote code execution vulnerability in AnyDesk 5.5.2.

PoC: gha-lab-5ed08d6a80

GitHub Actions workflow sandbox for CVE-2025-32953 reproduction

PoC: Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-

Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.

PoC: PoC-for-CVE-2025-46359

PoC CVE-2025-46359

PoC: CVE-2026-63039

Reproducer for CVE-2026-63039 (Apache InLong AuditAlertRule MyBatis ORDER BY SQL injection via orderField/orderType)

PoC: CVE-2026-28672

Reproducer for CVE-2026-28672 (Apache Ranger UnixUserGroupBuilder OS command injection via username in the unixusersync module)

PoC: CVE-2026-78329

Reproducer for CVE-2026-78329 (Apache Camel camel-undertow header filter strategy not applied, websocket.* injection) — Camel Spring Boot

PoC: CVE-2026-71300

Reproducer for CVE-2026-71300 (Apache Camel camel-atmosphere-websocket dispatch header injection) — Camel Spring Boot

PoC: CVE-2026-60093

Reproducer for CVE-2026-60093 (Apache Camel camel-azure-storage-datalake downloadToFile path traversal) — Camel Spring Boot + Camel Quarkus

PoC: CVE-2026-66906

Reproducer for CVE-2026-66906 (Apache Camel camel-azure-storage-blob downloadBlobToFile path traversal) — Camel Spring Boot + Camel Quarkus

PoC: CVE-2026-66907

Reproducer for CVE-2026-66907 (Apache Camel camel-google-storage downloadFileName path traversal) — Camel Spring Boot + Camel Quarkus

PoC: CVE-2026-66908

Reproducer for CVE-2026-66908 (Apache Camel camel-platform-http-main JWT iss/aud not validated) — standalone camel-main

PoC: CVE-2026-68820-Mitigation-PoC-

Este repositorio contiene una demostración educativa de la mitigación para **CVE-2026-68820**, una vulnerabilidad crítica de tipo **Use-After-Free (UAF)** en el driver `afd.sys` de Windows.

PoC: CVE-2026-63621

Reproducer for CVE-2026-63621 (Apache Camel camel-knative structured CloudEvent header injection) — Camel Spring Boot + Camel Quarkus

PoC: CVE-2026-59230

Reproducer for CVE-2026-59230 (Apache Camel camel-mail MimeMultipart headersInline header injection) — Camel Spring Boot + Camel Quarkus

PoC: gha-lab-16bfb18428

GitHub Actions workflow sandbox for CVE-2024-45798 reproduction

PoC: CVE-2026-73570

CVE-2026-73570 PoC

PoC: CVE-2018-5803

Lab for testing CVE-2018-5803

PoC: ghostlock-k419-adapter

GhostLock (CVE-2026-43499) adapter for 4.19.152-perf+ Android kernel

PoC: CVE-2026-43499-NAM-AL00

Security research: CVE-2026-43499 GhostLock on Huawei Nova 9 NAM-AL00 (SM7325, HMOS 4.2, kernel 5.4.86-qgki)

PoC: CVE-2025-48595-Exploit

CVE-2025-48595 Android Framework Integer Overflow PoC - 优化版

PoC: CVE-2025-55182

SIMPLE EXPOIT FOR CVE-2025-55182 FOR RCE , COMMAND INJECTIONS AND OTHER VULNERABILITIES

PoC: CVE-2022-2590-analysis

Dirty COW restricted to shmem in linux kernel (CVE-2022-2590) analysis

PoC: patch-CVE-2024-55890

Patch: Sandbox escape (macOS Kernel)

PoC: patch-CVE-2024-66001

Patch: Privilege escalation (Windows Print Spooler)

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free