Impact
Zebra versions prior to 4.4.0 contain a consensus‑divergence flaw in the V5 transparent signature verification logic. The implementation mistakenly computes a ZIP‑244 digest for SIGHASH_SINGLE transactions that have no corresponding output, instead of failing as expected. Attackers can therefore craft V5 transactions that contain these through the getblocktemplate RPC interface, and produce blocks that Zebra will append to its chain while the reference implementation, zcashd, will reject. This divergence causes temporary forks and can disrupt network consensus.
Affected Systems
All Zebra nodes running a build before version 4.4.0 are affected. The vulnerability is specific to the Zcash Foundation’s Zebra client and does not impact other Zcash full‑node implementations. No additional product variants are listed in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 8.3. No EPSS score is available at this time and it is not published in the CISA KEV catalog. The attack requires the ability to submit a malicious block template to a Zebra node, which typically occurs through the public getblocktemplate RPC. Based on the description, it is inferred that a remote attacker with access to a mining client interface could exploit this flaw, resulting in a split consensus and potential loss of blockchain integrity.
OpenCVE Enrichment