ZcashFoundation zebra
18 known vulnerabilities in ZcashFoundation zebra, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-104437 CVSS 8.3 high Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for…
- CVE-2026-104436 CVSS 6.3 medium Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool…
- CVE-2026-104435 CVSS 8.3 high Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with…
- CVE-2026-104434 CVSS 7.1 high ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC…
- CVE-2026-104432 CVSS 6.9 medium Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks…
- CVE-2026-104431 CVSS 8.7 high Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting…
- CVE-2026-104430 CVSS 8.7 high Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH…
- CVE-2026-104429 CVSS 6.9 medium Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx…
- CVE-2026-104428 CVSS 6.9 medium The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain…
- CVE-2026-104427 CVSS 8.2 high Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall…
- CVE-2026-104426 CVSS 8.2 high Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire…
- CVE-2026-104425 CVSS 6.9 medium ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block…
- CVE-2026-104424 CVSS 6.3 medium Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and…
- CVE-2026-104423 CVSS 8.7 high Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block…
- CVE-2026-104422 CVSS 8.7 high The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops…
- CVE-2026-104421 CVSS 6.9 medium Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by…
- CVE-2026-104420 CVSS 6.9 medium Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying…
- CVE-2026-104419 CVSS 6.3 medium Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior…