Impact
The vulnerability allows a malicious actor to construct a V5 transparent input transaction that uses the SIGHASH_SINGLE type but omits the required corresponding output. Because Zebra does not enforce the ZIP-244 consensus rule, the node will accept and relay the transaction while the canonical Zcash daemon (zcashd) will reject it. The acceptance of differing transaction sets by a subset of the network causes divergent block validations, leading to a consensus split and potential denial of service for normal users.
Affected Systems
The affected products are ZcashFoundation Zebra daemons (zebra and zebra-script). All releases of Zebra 4.4.0 and zebra-script 6.0.0 are impacted; later revisions are not explicitly noted in the advisory. Users running these versions on any operating system are at risk.
Risk and Exploitability
The CVSS score is 8.3, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to broadcast a crafted transaction; the attack can be performed by any community member with access to the network. Because it initiates a consensus divergence, the consequences can be systemic, affecting all connected nodes that accept the attacker's transaction.
OpenCVE Enrichment