Description
Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Consensus Divergence
Action: Immediate Patch
AI Analysis

Impact

Zebra nodes count P2SH redeem script signature operations in legacy mode, overcounting CHECKMULTISIG operations as 20 sigops when preceded by OP_1 through OP_16. This discrepancy allows an attacker to construct a transaction whose actual sigop count is within the block limit but the Zebra node rejects it as exceeding the inflated MAX_BLOCK_SIGOPS, leading to a consensus divergence. Nodes that reject such blocks become out‑of‑sync with the network, potentially causing a chain split and denying service to legitimate users.

Affected Systems

The affected products are ZcashFoundation Zebra zebrad version 4.5.0 and zebra‑script version 7.0.0. Only these versions contain the incorrect P2SH sigops counting logic and thus are susceptible to the described behavior.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity of the flaw. EPSS data is not available, so the current exploitation probability cannot be quantified. The flaw is listed as not in KEV. Attacks can be launched remotely by broadcasting a malicious transaction, so the likely attack vector is network transmission of a specially crafted transaction. Any node running the vulnerable ZcashFoundation Zebra versions can be impacted if it accepts a block that zcashd treats as valid. The risk is that an attacker could repeatedly send such transactions to cause nodes to reject blocks, leading to a persistent network split.

Generated by OpenCVE AI on October 2, 2026 at 12:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Re‑configure node to use the same MAX_BLOCK_SIGOPS threshold as zcashd or validate transactions locally before accepting blocks
  • Implement monitoring to detect and alert on frequent block rejections or consensus divergence
  • If an immediate upgrade is not possible, consider temporarily disabling or segregating the affected node from the network until the fix is applied

Generated by OpenCVE AI on October 2, 2026 at 12:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.
Title Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-628
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T15:17:44.203Z

Reserved: 2026-10-02T00:50:26.603Z

Link: CVE-2026-104430

cve-icon Vulnrichment

Updated: 2026-10-02T15:17:38.799Z

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:13.467

Modified: 2026-10-02T16:16:45.750

Link: CVE-2026-104430

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:15:15Z

Weaknesses
  • CWE-628

    Function Call with Incorrectly Specified Arguments