Description
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Published: 2026-10-02
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Consensus Split
Action: Immediate Patch
AI Analysis

Impact

Zebra versions prior to 4.4.0 contain a consensus‑divergence flaw in the V5 transparent signature verification logic. The implementation mistakenly computes a ZIP‑244 digest for SIGHASH_SINGLE transactions that have no corresponding output, instead of failing as expected. Attackers can therefore craft V5 transactions that contain these through the getblocktemplate RPC interface, and produce blocks that Zebra will append to its chain while the reference implementation, zcashd, will reject. This divergence causes temporary forks and can disrupt network consensus.

Affected Systems

All Zebra nodes running a build before version 4.4.0 are affected. The vulnerability is specific to the Zcash Foundation’s Zebra client and does not impact other Zcash full‑node implementations. No additional product variants are listed in the advisory.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3. No EPSS score is available at this time and it is not published in the CISA KEV catalog. The attack requires the ability to submit a malicious block template to a Zebra node, which typically occurs through the public getblocktemplate RPC. Based on the description, it is inferred that a remote attacker with access to a mining client interface could exploit this flaw, resulting in a split consensus and potential loss of blockchain integrity.

Generated by OpenCVE AI on October 2, 2026 at 12:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zebra to version 4.4.0 or later to apply the official fix.
  • If an update cannot be applied immediately, restrict the getblocktemplate RPC to trusted miners only or disable the service entirely to prevent the submission of malicious block templates.
  • Ensure all peer nodes in the network run the patched version and monitor block acceptance rates for signs of consensus divergence.

Generated by OpenCVE AI on October 2, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Zcashfoundation
Zcashfoundation zebra
Vendors & Products Zcashfoundation
Zcashfoundation zebra

Fri, 02 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
Description Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Title Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling
First Time appeared Zfnd
Zfnd zebra
Weaknesses CWE-347
CPEs cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
Vendors & Products Zfnd
Zfnd zebra
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-02T11:38:13.855Z

Reserved: 2026-10-02T00:50:26.604Z

Link: CVE-2026-104437

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T12:17:14.357

Modified: 2026-10-02T12:17:14.357

Link: CVE-2026-104437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T13:00:13Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature