Description
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Published: 2026-10-02
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Consensus split via crafted V5 transaction
Action: Immediate Update
AI Analysis

Impact

The vulnerability allows a malicious actor to construct a V5 transparent input transaction that uses the SIGHASH_SINGLE type but omits the required corresponding output. Because Zebra does not enforce the ZIP-244 consensus rule, the node will accept and relay the transaction while the canonical Zcash daemon (zcashd) will reject it. The acceptance of differing transaction sets by a subset of the network causes divergent block validations, leading to a consensus split and potential denial of service for normal users.

Affected Systems

The affected products are ZcashFoundation Zebra daemons (zebra and zebra-script). All releases of Zebra 4.4.0 and zebra-script 6.0.0 are impacted; later revisions are not explicitly noted in the advisory. Users running these versions on any operating system are at risk.

Risk and Exploitability

The CVSS score is 8.3, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to broadcast a crafted transaction; the attack can be performed by any community member with access to the network. Because it initiates a consensus divergence, the consequences can be systemic, affecting all connected nodes that accept the attacker's transaction.

Generated by OpenCVE AI on October 2, 2026 at 12:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Zebra to a patched version that enforces ZIP-244 rules and rejects V5 SIGHASH_SINGLE transactions without matching outputs
  • Apply any network-level transaction validation filters recommended by ZcashFoundation to reject suspicious V5 transactions before relay
  • Monitor the network for evidence of consensus splits or orphaned blocks, and coordinate with the community to trigger a rollback if a split occurs

Generated by OpenCVE AI on October 2, 2026 at 12:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Title Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-347
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:12.487Z

Reserved: 2026-10-02T00:50:26.604Z

Link: CVE-2026-104435

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:14.063

Modified: 2026-10-02T12:17:14.063

Link: CVE-2026-104435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:30:05Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature