Search

Find a vulnerability

Search criteria

    41 vulnerabilities by ZcashFoundation

    CVE-2026-104437 (GCVE-0-2026-104437)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
    VLAI
    Title
    Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling
    Summary
    Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
    CWE
    • CWE-347 - Improper Verification of Cryptographic Signature
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 4.4.0 (semver)
    Unaffected: 4.4.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-05-02 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "4.4.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "4.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.4.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "sangsoo-osec"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "defuse"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "mpguerra"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-05-02T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-347",
                  "description": "Improper Verification of Cryptographic Signature",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:13.855Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-cwfq-rfcr-8hmp)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-cwfq-rfcr-8hmp"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-4.4.0-consensus-split-via-sighash-single-missing-output-handling"
            }
          ],
          "title": "Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104437",
        "datePublished": "2026-10-02T11:38:13.855Z",
        "dateReserved": "2026-10-02T00:50:26.604Z",
        "dateUpdated": "2026-10-02T11:38:13.855Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104436 (GCVE-0-2026-104436)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 14:51
    VLAI
    Title
    Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length
    Summary
    Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 14:51 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 4.5.0 (semver)
    Unaffected: 4.5.0 (semver)
    Create a notification for this product.
    ZcashFoundation zebra Affected: 0 , < 8.0.0 (semver)
    Unaffected: 8.0.0 (semver)
    Create a notification for this product.
    Date Public
    2026-05-29 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104436",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T14:51:19.938453Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T14:51:28.130Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "4.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "4.5.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebra-chain",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "8.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "8.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.5.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "8.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "dingledropper"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "mpguerra"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "oxarbitrage"
            }
          ],
          "datePublic": "2026-05-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade block validation, RPC, and mempool performance."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:13.172Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-443g-gwgp-49x4)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-443g-gwgp-49x4"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-4.5.0-cpu-amplification-via-uncapped-getblocks-getheaders-locator-length"
            }
          ],
          "title": "Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104436",
        "datePublished": "2026-10-02T11:38:13.172Z",
        "dateReserved": "2026-10-02T00:50:26.604Z",
        "dateUpdated": "2026-10-02T14:51:28.130Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104435 (GCVE-0-2026-104435)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:16
    VLAI
    Title
    Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output
    Summary
    Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 15:16 UTC
    CWE
    • CWE-347 - Improper Verification of Cryptographic Signature
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 4.4.0 , < 4.4.1 (semver)
    Unaffected: 4.4.1 (semver)
    Create a notification for this product.
    ZcashFoundation zebra Affected: 6.0.0 , < 6.0.1 (semver)
    Unaffected: 6.0.1 (semver)
    Create a notification for this product.
    Date Public
    2026-05-04 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104435",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T15:16:28.895399Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T15:16:42.729Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "4.4.1",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "4.4.1",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebra-script",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.0.1",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.0.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.4.1",
                      "versionStartIncluding": "4.4.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.0.1",
                      "versionStartIncluding": "6.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "sangsoo-osec"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "fivelittleducks"
            }
          ],
          "datePublic": "2026-05-04T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-347",
                  "description": "Improper Verification of Cryptographic Signature",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:12.487Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-pvmv-cwg8-v6c8)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-pvmv-cwg8-v6c8"
            },
            {
              "name": "VulnCheck Advisory: Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-4.4.0-consensus-divergence-via-v5-sighash-single-without-output"
            }
          ],
          "title": "Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104435",
        "datePublished": "2026-10-02T11:38:12.487Z",
        "dateReserved": "2026-10-02T00:50:26.604Z",
        "dateUpdated": "2026-10-02T15:16:42.729Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104434 (GCVE-0-2026-104434)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:30
    VLAI
    Title
    Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC
    Summary
    ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 15:28 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 8.0.0 (semver)
    Unaffected: 8.0.0 (semver)
    Create a notification for this product.
    ZcashFoundation zebra Affected: 0 , < 4.5.0 (semver)
    Unaffected: 4.5.0 (semver)
    Create a notification for this product.
    Date Public
    2026-05-29 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104434",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T15:28:55.986876Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T15:30:07.619Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebra-rpc",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "8.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "8.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "4.5.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "4.5.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "8.0.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.5.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "robustfengbin"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "mpguerra"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-05-29T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-617",
                  "description": "Reachable Assertion",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:11.845Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-c8w6-x74f-vmg3)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-c8w6-x74f-vmg3"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-8.0.0-denial-of-service-via-z-listunifiedreceivers-rpc"
            }
          ],
          "title": "Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104434",
        "datePublished": "2026-10-02T11:38:11.845Z",
        "dateReserved": "2026-10-02T00:50:26.604Z",
        "dateUpdated": "2026-10-02T15:30:07.619Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104432 (GCVE-0-2026-104432)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
    VLAI
    Title
    Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response
    Summary
    Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip.
    CWE
    • CWE-754 - Improper Check for Unusual or Exceptional Conditions
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.3.0 (semver)
    Unaffected: 6.3.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/Zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.3.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.3.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "Maakai123"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "oxarbitrage"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node remains behind the tip."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-754",
                  "description": "Improper Check for Unusual or Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:11.214Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-h8m8-844p-v3m9)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-h8m8-844p-v3m9"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-false-readiness-via-discarded-one-hash-findblocks-response"
            }
          ],
          "title": "Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104432",
        "datePublished": "2026-10-02T11:38:11.214Z",
        "dateReserved": "2026-10-02T00:50:26.603Z",
        "dateUpdated": "2026-10-02T11:38:11.214Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104431 (GCVE-0-2026-104431)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 14:53
    VLAI
    Title
    Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification
    Summary
    Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 14:53 UTC
    CWE
    • CWE-405 - Asymmetric Resource Consumption (Amplification)
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.0.0 (semver)
    Unaffected: 6.0.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-13 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104431",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T14:53:45.702420Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T14:53:54.651Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ouicate"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "conradoplg"
            }
          ],
          "datePublic": "2026-07-13T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresponsive."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-405",
                  "description": "Asymmetric Resource Consumption (Amplification)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:10.560Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-84j3-rw4c-gqmj)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-84j3-rw4c-gqmj"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.0.0-denial-of-service-via-synchronous-script-ffi-verification"
            }
          ],
          "title": "Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104431",
        "datePublished": "2026-10-02T11:38:10.560Z",
        "dateReserved": "2026-10-02T00:50:26.603Z",
        "dateUpdated": "2026-10-02T14:53:54.651Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104430 (GCVE-0-2026-104430)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:17
    VLAI
    Title
    Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount
    Summary
    Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 15:17 UTC
    CWE
    • CWE-628 - Function Call with Incorrectly Specified Arguments
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 4.5.0 , < 4.5.1 (semver)
    Unaffected: 4.5.1 (semver)
    Create a notification for this product.
    ZcashFoundation zebra Affected: 7.0.0 , < 7.0.1 (semver)
    Unaffected: 7.0.1 (semver)
    Create a notification for this product.
    Date Public
    2026-06-01 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104430",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T15:17:26.296433Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T15:17:44.203Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "4.5.1",
                  "status": "affected",
                  "version": "4.5.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "4.5.1",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebra-script",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "7.0.1",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "7.0.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "4.5.1",
                      "versionStartIncluding": "4.5.0",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "7.0.1",
                      "versionStartIncluding": "7.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "sangsoo-osec"
            }
          ],
          "datePublic": "2026-06-01T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd\u0027s accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra\u0027s inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-628",
                  "description": "Function Call with Incorrectly Specified Arguments",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:09.916Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-2prc-cj5x-4443)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2prc-cj5x-4443"
            },
            {
              "name": "VulnCheck Advisory: Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-4.5.0-consensus-split-via-p2sh-sigop-overcount"
            }
          ],
          "title": "Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104430",
        "datePublished": "2026-10-02T11:38:09.916Z",
        "dateReserved": "2026-10-02T00:50:26.603Z",
        "dateUpdated": "2026-10-02T15:17:44.203Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104429 (GCVE-0-2026-104429)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 12:27
    VLAI
    Title
    Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages
    Summary
    Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers' transaction relay.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 12:27 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.0.0-rc.0 (semver)
    Unaffected: 6.0.0-rc.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-03 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104429",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T12:27:13.306414Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T12:27:23.589Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.0.0-rc.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.0.0-rc.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.0.0-rc.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "SuplabsYi"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "oxarbitrage"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "mpguerra"
            }
          ],
          "datePublic": "2026-07-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool admission slots, crowding out honest peers\u0027 transaction relay."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:09.257Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-m9xx-8rcj-vmgp)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-m9xx-8rcj-vmgp"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.0.0-rc.0-per-peer-mempool-admission-bypass-via-p2p-tx-messages"
            }
          ],
          "title": "Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104429",
        "datePublished": "2026-10-02T11:38:09.257Z",
        "dateReserved": "2026-10-02T00:46:23.831Z",
        "dateUpdated": "2026-10-02T12:27:23.589Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104428 (GCVE-0-2026-104428)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
    VLAI
    Title
    Zebra before 11.0.0 Denial of Service via getblock Verbosity 2
    Summary
    The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop.
    CWE
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 11.0.0 (semver)
    Unaffected: 11.0.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-03 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebra-rpc",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "11.0.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "11.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "11.0.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "coordinator",
              "value": "mpguerra"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "defuse"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "oxarbitrage"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-07-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation\u0027s Zebra node, panics on verbosity 2 for a side-chain block because the block\u0027s -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can repeat this call to keep the node in a crash loop."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-617",
                  "description": "Reachable Assertion",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:08.558Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-x6v8-c2xp-928m)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-x6v8-c2xp-928m"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 11.0.0 Denial of Service via getblock Verbosity 2",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-11.0.0-denial-of-service-via-getblock-verbosity-2"
            }
          ],
          "title": "Zebra before 11.0.0 Denial of Service via getblock Verbosity 2",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104428",
        "datePublished": "2026-10-02T11:38:08.558Z",
        "dateReserved": "2026-10-02T00:46:23.831Z",
        "dateUpdated": "2026-10-02T11:38:08.558Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104427 (GCVE-0-2026-104427)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
    VLAI
    Title
    Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry
    Summary
    Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks.
    CWE
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.1.0 (semver)
    Unaffected: 6.1.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-17 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.1.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "deedim"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "jvff"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-07-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block\u0027s hash before it propagates, causing the next canonical block to be rejected and stalling the node for roughly 2,000 blocks."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:07.777Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-8gxx-hc65-vv82)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8gxx-hc65-vv82"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-chain-stall-via-stale-parent-error-map-entry"
            }
          ],
          "title": "Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104427",
        "datePublished": "2026-10-02T11:38:07.777Z",
        "dateReserved": "2026-10-02T00:46:23.831Z",
        "dateUpdated": "2026-10-02T11:38:07.777Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104426 (GCVE-0-2026-104426)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:18
    VLAI
    Title
    Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check
    Summary
    Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 15:18 UTC
    CWE
    • CWE-407 - Inefficient Algorithmic Complexity
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.1.0 (semver)
    Unaffected: 6.1.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104426",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T15:18:27.097171Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T15:18:42.536Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.1.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ValarDragon"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "oxarbitrage"
            }
          ],
          "datePublic": "2026-07-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block, stalling every validating node for over 52 seconds."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-407",
                  "description": "Inefficient Algorithmic Complexity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:07.187Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-4g24-549m-hp75)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4g24-549m-hp75"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-quadratic-complexity-dos-via-block-transparent-value-check"
            }
          ],
          "title": "Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104426",
        "datePublished": "2026-10-02T11:38:07.187Z",
        "dateReserved": "2026-10-02T00:46:23.830Z",
        "dateUpdated": "2026-10-02T15:18:42.536Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104425 (GCVE-0-2026-104425)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:35
    VLAI
    Title
    Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions
    Summary
    ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 15:34 UTC
    CWE
    • CWE-405 - Asymmetric Resource Consumption (Amplification)
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.1.0 (semver)
    Unaffected: 6.1.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104425",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T15:34:04.808428Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T15:35:22.404Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.1.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ValarDragon"
            },
            {
              "lang": "en",
              "type": "reporter",
              "value": "ebfull"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-07-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing honest block proofs onto the slow individual-verification path and slowing block processing roughly sevenfold."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-405",
                  "description": "Asymmetric Resource Consumption (Amplification)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:06.504Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-g7c4-2w6c-cr3r)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-g7c4-2w6c-cr3r"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-batch-verification-poisoning-dos-via-unattributed-pushed-transactions"
            }
          ],
          "title": "Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104425",
        "datePublished": "2026-10-02T11:38:06.504Z",
        "dateReserved": "2026-10-02T00:46:23.830Z",
        "dateUpdated": "2026-10-02T15:35:22.404Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104424 (GCVE-0-2026-104424)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
    VLAI
    Title
    Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate
    Summary
    Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work.
    CWE
    • CWE-131 - Incorrect Calculation of Buffer Size
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.1.0 (semver)
    Unaffected: 6.1.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-17 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.1.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.1.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ebfull"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-07-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner\u0027s mempool to shape templates into oversized blocks, causing rejection and wasted proof-of-work."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 3.7,
                "baseSeverity": "LOW",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-131",
                  "description": "Incorrect Calculation of Buffer Size",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:05.827Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-95m2-vx53-v2jw)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-95m2-vx53-v2jw"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.1.0-incorrect-block-size-calculation-in-getblocktemplate"
            }
          ],
          "title": "Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104424",
        "datePublished": "2026-10-02T11:38:05.827Z",
        "dateReserved": "2026-10-02T00:46:23.830Z",
        "dateUpdated": "2026-10-02T11:38:05.827Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104423 (GCVE-0-2026-104423)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 15:55
    VLAI
    Title
    Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification
    Summary
    Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 15:55 UTC
    CWE
    • CWE-405 - Asymmetric Resource Consumption (Amplification)
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.2.1 (semver)
    Unaffected: 6.2.1 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-17 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104423",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T15:55:46.130893Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T15:55:54.144Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.2.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.2.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.2.1",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "craftsoldier"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "conradoplg"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-08-17T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying zero-filled Orchard and Ironwood proofs, causing nodes to fall behind the chain tip."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-405",
                  "description": "Asymmetric Resource Consumption (Amplification)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:05.140Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-2p4c-3q4q-p463)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2p4c-3q4q-p463"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.2.1-denial-of-service-via-uncapped-v6-shielded-proof-verification"
            }
          ],
          "title": "Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104423",
        "datePublished": "2026-10-02T11:38:05.140Z",
        "dateReserved": "2026-10-02T00:46:23.830Z",
        "dateUpdated": "2026-10-02T15:55:54.144Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104422 (GCVE-0-2026-104422)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 17:35
    VLAI
    Title
    Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite
    Summary
    The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node's discovery of the newest block.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 17:34 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.3.0 (semver)
    Unaffected: 6.3.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-11 00:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104422",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T17:34:45.949504Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T17:35:03.530Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/Zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.3.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.3.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "upbqdn"
            }
          ],
          "datePublic": "2026-08-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The block sync download path in Zebra (zebrad) before 6.3.0 reads a block\u0027s height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can repeatedly serve a canonical block whose coinbase claims height 1 while keeping the requested hash, delaying the node\u0027s discovery of the newest block."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:03.646Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-g95h-hw6g-pvgv)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-g95h-hw6g-pvgv"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-block-sync-denial-of-service-via-coinbase-scriptsig-rewrite"
            }
          ],
          "title": "Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104422",
        "datePublished": "2026-10-02T11:38:03.646Z",
        "dateReserved": "2026-10-02T00:46:23.830Z",
        "dateUpdated": "2026-10-02T17:35:03.530Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104421 (GCVE-0-2026-104421)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 12:28
    VLAI
    Title
    Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout
    Summary
    Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 12:27 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.2.1 (semver)
    Unaffected: 6.2.1 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-07-22 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104421",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T12:27:43.846358Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T12:28:10.585Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.2.1",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.2.1",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.2.1",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "datePublic": "2026-07-22T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block\u0027s header hash, causing Request::KnownBlock to skip the honest block and keep nodes behind the tip."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:02.456Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-x93j-mj2f-q338)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-x93j-mj2f-q338"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.2.1-block-download-denial-of-service-via-knownblock-senthashes-lockout"
            }
          ],
          "title": "Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104421",
        "datePublished": "2026-10-02T11:38:02.456Z",
        "dateReserved": "2026-10-02T00:46:23.830Z",
        "dateUpdated": "2026-10-02T12:28:10.585Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104420 (GCVE-0-2026-104420)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
    VLAI
    Title
    Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks
    Summary
    Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned.
    CWE
    • CWE-704 - Incorrect Type Conversion or Cast
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.3.0 (semver)
    Unaffected: 6.3.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-11 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.3.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.3.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "evan-forbes"
            }
          ],
          "datePublic": "2026-08-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and Equihash verification without being banned."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-704",
                  "description": "Incorrect Type Conversion or Cast",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:01.836Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-8hh2-hrf2-cqf4)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8hh2-hrf2-cqf4"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-peer-misbehavior-ban-bypass-via-gossiped-blocks"
            }
          ],
          "title": "Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104420",
        "datePublished": "2026-10-02T11:38:01.836Z",
        "dateReserved": "2026-10-02T00:46:23.830Z",
        "dateUpdated": "2026-10-02T11:38:01.836Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104419 (GCVE-0-2026-104419)

    Vulnerability from cvelistv5 – Published: 2026-10-02 11:38 – Updated: 2026-10-02 11:38
    VLAI
    Title
    Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes
    Summary
    Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: 0 , < 6.3.0 (semver)
    Unaffected: 6.3.0 (semver)
        cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2026-08-11 00:00
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "packageURL": "pkg:cargo/zebrad",
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "lessThan": "6.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "status": "unaffected",
                  "version": "6.3.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.3.0",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "zakura-security"
            }
          ],
          "datePublic": "2026-08-11T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "LOW"
              },
              "format": "CVSS"
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T11:38:01.103Z",
            "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
            "shortName": "VulnCheck"
          },
          "references": [
            {
              "name": "GitHub Security Advisory (GHSA-qhr3-cvch-5fh2)",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-qhr3-cvch-5fh2"
            },
            {
              "name": "VulnCheck Advisory: Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.vulncheck.com/advisories/zebra-before-6.3.0-honest-peer-banning-via-far-ahead-findblocks-hashes"
            }
          ],
          "title": "Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes",
          "x_generator": {
            "engine": "vulncheck-endgame"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "assignerShortName": "VulnCheck",
        "cveId": "CVE-2026-104419",
        "datePublished": "2026-10-02T11:38:01.103Z",
        "dateReserved": "2026-10-02T00:44:44.529Z",
        "dateUpdated": "2026-10-02T11:38:01.103Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52829 (GCVE-0-2026-52829)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:27 – Updated: 2026-08-18 19:44
    VLAI
    Title
    ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized an IPv4-mapped IPv6 PeerSocketAddr such as ::ffff:127.0.0.1 to plain IPv4 before storing it through MetaAddr::new_connected, but the mempool misbehavior path forwarded the raw transient address to MetaAddrChange::UpdateMisbehavior. In zebra-network/src/meta_addr.rs, apply_to_meta_addr then compared the canonical address-book entry with the raw update address and reached its unexpected address mismatch assertion. After the misbehavior batch flush, panic equals abort terminated zebrad; the peer only needed to complete a P2P handshake and advertise an invalid mempool transaction. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 19:44 UTC
    CWE
    • CWE-617 - Reachable Assertion
    • CWE-843 - Access of Resource Using Incompatible Type ('Type Confusion')
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: < 4.5.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52829",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T19:44:48.869272Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-18T19:44:56.318Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized an IPv4-mapped IPv6 PeerSocketAddr such as ::ffff:127.0.0.1 to plain IPv4 before storing it through MetaAddr::new_connected, but the mempool misbehavior path forwarded the raw transient address to MetaAddrChange::UpdateMisbehavior. In zebra-network/src/meta_addr.rs, apply_to_meta_addr then compared the canonical address-book entry with the raw update address and reached its unexpected address mismatch assertion. After the misbehavior batch flush, panic equals abort terminated zebrad; the peer only needed to complete a P2P handshake and advertise an invalid mempool transaction. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-617",
                  "description": "CWE-617: Reachable Assertion",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-843",
                  "description": "CWE-843: Access of Resource Using Incompatible Type (\u0027Type Confusion\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:27:57.318Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-63wg-wjjj-7cp8",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-63wg-wjjj-7cp8"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-63wg-wjjj-7cp8",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52829",
        "datePublished": "2026-08-18T19:27:57.318Z",
        "dateReserved": "2026-06-08T18:11:06.662Z",
        "dateUpdated": "2026-08-18T19:44:56.318Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52736 (GCVE-0-2026-52736)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:26 – Updated: 2026-08-18 19:38
    VLAI
    Title
    ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the attacker to mutate coinbase scriptSig authentication data while retaining the transaction identifiers, merkle root, and block header hash, so the poisoned body fails later commitment validation but shares the canonical hash. In zebra-state/src/service.rs, queue_and_commit_to_non_finalized_state recorded the hash in non_finalized_block_write_sent_hashes before contextual validation completed and did not remove it when the write task rejected the body. When the honest body later arrived, the cached hash caused KnownBlock::WriteChannel duplicate handling to suppress it, leaving the node stuck one height behind until restart or reorganization. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 19:38 UTC
    CWE
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: < 4.5.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52736",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T19:38:19.383112Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-18T19:38:44.395Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the attacker to mutate coinbase scriptSig authentication data while retaining the transaction identifiers, merkle root, and block header hash, so the poisoned body fails later commitment validation but shares the canonical hash. In zebra-state/src/service.rs, queue_and_commit_to_non_finalized_state recorded the hash in non_finalized_block_write_sent_hashes before contextual validation completed and did not remove it when the write task rejected the body. When the honest body later arrived, the cached hash caused KnownBlock::WriteChannel duplicate handling to suppress it, leaving the node stuck one height behind until restart or reorganization. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "CWE-459: Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:26:40.575Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4m69-67m6-prqp",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4m69-67m6-prqp"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-4m69-67m6-prqp",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52736",
        "datePublished": "2026-08-18T19:26:40.575Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-18T19:38:44.395Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52732 (GCVE-0-2026-52732)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:26 – Updated: 2026-08-18 19:32
    VLAI
    Title
    ZEBRA: Mempool transaction admission denial via single-peer inbound queue saturation
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/mempool/downloads.rs, the bounded queue was shared globally without per-peer accounting, while peer identity was not carried through Gossip and FullQueue responses were mapped to Response::Nil instead of reaching overload disconnection handling. An attacker can advertise fake transaction identifiers and remain silent so each task holds a slot until TRANSACTION_DOWNLOAD_TIMEOUT, then periodically refill the queue as slots expire. While saturated, honest peer transactions and local sendrawtransaction requests are rejected with MempoolError::FullQueue, although block validation and synchronization continue. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 19:32 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: < 4.5.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52732",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T19:32:12.651849Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-18T19:32:31.103Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4fc2-h7jh-287c"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra\u0027s inbound mempool download and verification pipeline. In zebrad/src/components/mempool/downloads.rs, the bounded queue was shared globally without per-peer accounting, while peer identity was not carried through Gossip and FullQueue responses were mapped to Response::Nil instead of reaching overload disconnection handling. An attacker can advertise fake transaction identifiers and remain silent so each task holds a slot until TRANSACTION_DOWNLOAD_TIMEOUT, then periodically refill the queue as slots expire. While saturated, honest peer transactions and local sendrawtransaction requests are rejected with MempoolError::FullQueue, although block validation and synchronization continue. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770: Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:26:07.345Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4fc2-h7jh-287c",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-4fc2-h7jh-287c"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-4fc2-h7jh-287c",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Mempool transaction admission denial via single-peer inbound queue saturation"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52732",
        "datePublished": "2026-08-18T19:26:07.345Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-18T19:32:31.103Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52731 (GCVE-0-2026-52731)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:25 – Updated: 2026-08-18 19:42
    VLAI
    Title
    ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str originally checked the input byte length and then sliced fixed byte ranges to parse encoded fields. A slice boundary can land inside a multi-byte character and trigger Rust's byte index is not a char boundary panic. Zebra release builds use panic equals abort, so one malformed authenticated RPC request terminates the entire node process and can be repeated after restart. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 19:38 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52731",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T19:38:59.310629Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-18T19:42:08.415Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            },
            {
              "product": "zebra-rpc",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 8.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-rpc/src/methods/types/long_poll.rs, LongPollId::from_str originally checked the input byte length and then sliced fixed byte ranges to parse encoded fields. A slice boundary can land inside a multi-byte character and trigger Rust\u0027s byte index is not a char boundary panic. Zebra release builds use panic equals abort, so one malformed authenticated RPC request terminates the entire node process and can be repeated after restart. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-248",
                  "description": "CWE-248: Uncaught Exception",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:25:39.314Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-qv2r-v3mx-f4pf",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-qv2r-v3mx-f4pf"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-qv2r-v3mx-f4pf",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52731",
        "datePublished": "2026-08-18T19:25:39.314Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-18T19:42:08.415Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52733 (GCVE-0-2026-52733)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:24 – Updated: 2026-08-19 15:20
    VLAI
    Title
    ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did not remove subtree entries whose end_height belonged to that block, unlike the cleanup performed by pop_root. When the winning fork later finalized, the abandoned branch's stale subtree data could be written to RocksDB and survive node restarts. The corrupted history can cause z_getsubtreesbyindex consumers such as lightwalletd and light wallets to receive incorrect subtree roots, producing wallet synchronization failures or incorrect wallet state and requiring a full state rebuild for recovery. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-19 15:20 UTC
    CWE
    • CWE-459 - Incomplete Cleanup
    • CWE-672 - Operation on a Resource after Expiration or Release
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52733",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-19T15:20:08.584025Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-19T15:20:18.272Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            },
            {
              "product": "zebra-state",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 7.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::pop_tip removed a reverted tip block but did not remove subtree entries whose end_height belonged to that block, unlike the cleanup performed by pop_root. When the winning fork later finalized, the abandoned branch\u0027s stale subtree data could be written to RocksDB and survive node restarts. The corrupted history can cause z_getsubtreesbyindex consumers such as lightwalletd and light wallets to receive incorrect subtree roots, producing wallet synchronization failures or incorrect wallet state and requiring a full state rebuild for recovery. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-459",
                  "description": "CWE-459: Incomplete Cleanup",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-672",
                  "description": "CWE-672: Operation on a Resource after Expiration or Release",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:24:44.005Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2gf8-q9rr-jq3h",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2gf8-q9rr-jq3h"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-2gf8-q9rr-jq3h",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52733",
        "datePublished": "2026-08-18T19:24:44.005Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-19T15:20:18.272Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52738 (GCVE-0-2026-52738)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:24 – Updated: 2026-08-19 15:19
    VLAI
    Title
    ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address can permanently halt Zebra nodes. In zebra-state/src/service/finalized_state/zebra_db/transparent.rs, the finalized-state writer originally applied every newly created output as a credit before applying any spent-output debit from the same block. That credit-first ordering can make the intermediate per-address balance exceed MAX_MONEY even though the final net balance is valid, causing an expect-based panic under the panic equals abort release profile. Because zcashd accepts the triggering block and Zebra encounters it again after every restart, the halt persists until patched software is deployed; exploitation requires mining the specially constructed block and temporarily committing sufficient ZEC to the self-spend chain. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-19 15:18 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52738",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-19T15:18:53.096673Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-19T15:19:04.654Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            },
            {
              "product": "zebra-state",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 7.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address can permanently halt Zebra nodes. In zebra-state/src/service/finalized_state/zebra_db/transparent.rs, the finalized-state writer originally applied every newly created output as a credit before applying any spent-output debit from the same block. That credit-first ordering can make the intermediate per-address balance exceed MAX_MONEY even though the final net balance is valid, causing an expect-based panic under the panic equals abort release profile. Because zcashd accepts the triggering block and Zebra encounters it again after every restart, the halt persists until patched software is deployed; exploitation requires mining the specially constructed block and temporarily committing sufficient ZEC to the self-spend chain. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-248",
                  "description": "CWE-248: Uncaught Exception",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:24:04.945Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-w834-cf6p-9m9w",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-w834-cf6p-9m9w"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-w834-cf6p-9m9w",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52738",
        "datePublished": "2026-08-18T19:24:04.945Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-19T15:19:04.654Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52735 (GCVE-0-2026-52735)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:23 – Updated: 2026-08-18 19:48
    VLAI
    Title
    ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcodes. In zebra-script/src/lib.rs, p2sh_input_sigop_count used the pure-Rust script::Code::sig_op_count path, whose try_fold parser stops at disabled opcodes such as OP_CODESEPARATOR and returns only the partial count accumulated before the error. The zcashd reference implementation continues static signature-operation counting through disabled opcodes, so an attacker can broadcast P2SH spends that Zebra counts below MAX_BLOCK_SIGOPS while zcashd counts above the 20,000-operation limit. If a Zebra miner includes those transactions, Zebra validators accept the block while zcashd validators reject it, creating a consensus chain split that affects network integrity and availability without requiring the attacker to produce a block. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 19:48 UTC
    CWE
    • CWE-684 - Incorrect Provision of Specified Functionality
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: < 4.5.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52735",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T19:48:36.850142Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-18T19:48:45.150Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcodes. In zebra-script/src/lib.rs, p2sh_input_sigop_count used the pure-Rust script::Code::sig_op_count path, whose try_fold parser stops at disabled opcodes such as OP_CODESEPARATOR and returns only the partial count accumulated before the error. The zcashd reference implementation continues static signature-operation counting through disabled opcodes, so an attacker can broadcast P2SH spends that Zebra counts below MAX_BLOCK_SIGOPS while zcashd counts above the 20,000-operation limit. If a Zebra miner includes those transactions, Zebra validators accept the block while zcashd validators reject it, creating a consensus chain split that affects network integrity and availability without requiring the attacker to produce a block. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-684",
                  "description": "CWE-684: Incorrect Provision of Specified Functionality",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:23:10.705Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-gf9r-m956-97qx",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-gf9r-m956-97qx"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-gf9r-m956-97qx",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52735",
        "datePublished": "2026-08-18T19:23:10.705Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-18T19:48:45.150Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52739 (GCVE-0-2026-52739)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:22 – Updated: 2026-08-19 18:20
    VLAI
    Title
    ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::push originally inserted the transaction hash into tx_loc_by_hash and asserted uniqueness before updating shielded data and running the duplicate Sprout, Sapling, or Orchard nullifier checks. The repeated transaction therefore reached the transactions must be unique within a single chain assertion before contextual validation could reject it cleanly. Zebra release builds use panic equals abort, so the reachable assertion terminates the entire process; exploitation requires either two consecutive attacker-mined blocks or an attacker-mined child immediately after an honest block includes the attacker's shielded transaction. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-19 18:03 UTC
    CWE
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52739",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-19T18:03:57.639095Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-19T18:20:38.270Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            },
            {
              "product": "zebra-state",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 7.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::push originally inserted the transaction hash into tx_loc_by_hash and asserted uniqueness before updating shielded data and running the duplicate Sprout, Sapling, or Orchard nullifier checks. The repeated transaction therefore reached the transactions must be unique within a single chain assertion before contextual validation could reject it cleanly. Zebra release builds use panic equals abort, so the reachable assertion terminates the entire process; exploitation requires either two consecutive attacker-mined blocks or an attacker-mined child immediately after an honest block includes the attacker\u0027s shielded transaction. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-248",
                  "description": "CWE-248: Uncaught Exception",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:22:19.865Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-hhm7-qrv5-h4r6",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-hhm7-qrv5-h4r6"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-hhm7-qrv5-h4r6",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52739",
        "datePublished": "2026-08-18T19:22:19.865Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-19T18:20:38.270Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52734 (GCVE-0-2026-52734)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:19 – Updated: 2026-08-19 18:20
    VLAI
    Title
    ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/components/mempool/downloads.rs, Downloads::poll_next removed cancel_handles entries after success and ordinary verification errors, but tokio::time::error::Elapsed did not carry the UnminedTxId needed to remove the timed-out entry. Each retained cancel_handles entry could hold a full Gossip::Tx(UnminedTx), while normal mined-transaction cleanup could not match attacker transactions and no periodic garbage collection or count cap existed. Sustained traffic therefore caused monotonic memory growth until swap pressure degraded the node or the operating system terminated the zebrad process for exhausting memory. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-19 18:17 UTC
    CWE
    • CWE-401 - Missing Release of Memory after Effective Lifetime
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: < 4.5.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52734",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-19T18:17:27.998662Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-19T18:20:44.085Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/components/mempool/downloads.rs, Downloads::poll_next removed cancel_handles entries after success and ordinary verification errors, but tokio::time::error::Elapsed did not carry the UnminedTxId needed to remove the timed-out entry. Each retained cancel_handles entry could hold a full Gossip::Tx(UnminedTx), while normal mined-transaction cleanup could not match attacker transactions and no periodic garbage collection or count cap existed. Sustained traffic therefore caused monotonic memory growth until swap pressure degraded the node or the operating system terminated the zebrad process for exhausting memory. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-401",
                  "description": "CWE-401: Missing Release of Memory after Effective Lifetime",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:19:56.546Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-65jj-fmw8-468q",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-65jj-fmw8-468q"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-65jj-fmw8-468q",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52734",
        "datePublished": "2026-08-18T19:19:56.546Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-19T18:20:44.085Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52737 (GCVE-0-2026-52737)

    Vulnerability from cvelistv5 – Published: 2026-08-18 19:19 – Updated: 2026-08-18 19:33
    VLAI
    Title
    ZEBRA: Sync restart poisoning from single unauthenticated peer via above-lookahead block
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block whose coinbase height is far above the local chain tip. In zebrad/src/components/sync/downloads.rs, BlockDownloadVerifyError::AboveLookaheadHeightLimit originally carried only the block height and hash, so handle_block_response could not attribute the failure to the advertising peer. The error then reached the restart-worthy default path in zebrad/src/components/sync.rs, cancelling all in-flight downloads from honest peers and imposing a 67-second sync restart delay on mainnet. Because the peer was neither scored nor disconnected, the peer could repeat the cycle indefinitely with minimal bandwidth and significantly degrade synchronization without corrupting state. This issue is fixed in version 4.5.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-18 19:33 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52737",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-18T19:33:21.510952Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-18T19:33:34.092Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.5.0"
                }
              ]
            },
            {
              "product": "zebra-consensus",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 7.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra\u0027s outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block whose coinbase height is far above the local chain tip. In zebrad/src/components/sync/downloads.rs, BlockDownloadVerifyError::AboveLookaheadHeightLimit originally carried only the block height and hash, so handle_block_response could not attribute the failure to the advertising peer. The error then reached the restart-worthy default path in zebrad/src/components/sync.rs, cancelling all in-flight downloads from honest peers and imposing a 67-second sync restart delay on mainnet. Because the peer was neither scored nor disconnected, the peer could repeat the cycle indefinitely with minimal bandwidth and significantly degrade synchronization without corrupting state. This issue is fixed in version 4.5.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "CWE-345: Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-18T19:19:09.625Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-gvjc-3w7c-92jx",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-gvjc-3w7c-92jx"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/pull/10647",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/pull/10647"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cd"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/commit/bc64dfe45746a86d14546a0a5a766387dd5a2942",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/commit/bc64dfe45746a86d14546a0a5a766387dd5a2942"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v4.5.0"
            }
          ],
          "source": {
            "advisory": "GHSA-gvjc-3w7c-92jx",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Sync restart poisoning from single unauthenticated peer via above-lookahead block"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-52737",
        "datePublished": "2026-08-18T19:19:09.625Z",
        "dateReserved": "2026-06-08T14:00:43.572Z",
        "dateUpdated": "2026-08-18T19:33:34.092Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54496 (GCVE-0-2026-54496)

    Vulnerability from cvelistv5 – Published: 2026-07-17 16:59 – Updated: 2026-07-17 17:23
    VLAI
    Title
    Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying it to the actual base, allowing a malicious prover to produce a valid proof for an Orchard Action with an under-constrained base point and bypass the diversified-address-integrity check that binds pk_d, g_d, ivk, the nullifier (nf), and the spend validating key (ak) to the note being spent. This issue is fixed in zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-17 17:23 UTC
    CWE
    • CWE-345 - Insufficient Verification of Data Authenticity
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54496",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-17T17:23:34.445671Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-17T17:23:50.731Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 5.0.0"
                }
              ]
            },
            {
              "product": "halo2_gadgets",
              "vendor": "zcash",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 0.5.0"
                }
              ]
            },
            {
              "product": "orchard",
              "vendor": "zcash",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 0.14.0"
                }
              ]
            },
            {
              "product": "librustzcash",
              "vendor": "zcash",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 0.28.0"
                }
              ]
            },
            {
              "product": "zcash",
              "vendor": "zcash",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 6.20.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying it to the actual base, allowing a malicious prover to produce a valid proof for an Orchard Action with an under-constrained base point and bypass the diversified-address-integrity check that binds pk_d, g_d, ivk, the nullifier (nf), and the spend validating key (ak) to the note being spent. This issue is fixed in zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "CWE-345: Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-17T16:59:06.809Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-ww9q-8r59-xv46",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-ww9q-8r59-xv46"
            },
            {
              "name": "https://github.com/ZcashFoundation/zebra/releases/tag/v5.0.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/releases/tag/v5.0.0"
            },
            {
              "name": "https://github.com/zcash/halo2/releases/tag/halo2_gadgets-0.5.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zcash/halo2/releases/tag/halo2_gadgets-0.5.0"
            },
            {
              "name": "https://github.com/zcash/librustzcash/releases/tag/zcash_primitives-0.28.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zcash/librustzcash/releases/tag/zcash_primitives-0.28.0"
            },
            {
              "name": "https://github.com/zcash/orchard/releases/tag/0.14.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zcash/orchard/releases/tag/0.14.0"
            },
            {
              "name": "https://github.com/zcash/zcash/releases/tag/v6.20.0",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/zcash/zcash/releases/tag/v6.20.0"
            },
            {
              "name": "https://zfnd.org/zebra-4-5-3-and-5-0-0-emergency-soft-fork-and-nu6-2-activation",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://zfnd.org/zebra-4-5-3-and-5-0-0-emergency-soft-fork-and-nu6-2-activation"
            }
          ],
          "source": {
            "advisory": "GHSA-ww9q-8r59-xv46",
            "discovery": "UNKNOWN"
          },
          "title": "Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54496",
        "datePublished": "2026-07-17T16:59:06.809Z",
        "dateReserved": "2026-06-15T18:01:15.511Z",
        "dateUpdated": "2026-07-17T17:23:50.731Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-44499 (GCVE-0-2026-44499)

    Vulnerability from cvelistv5 – Published: 2026-05-08 15:11 – Updated: 2026-05-08 17:23
    VLAI
    Title
    ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
    Summary
    ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems — all exercisable from a single TCP connection — to create a monotonically growing block deficit that never self-heals. This issue has been patched in version 4.4.0.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-05-08 16:45 UTC
    CWE
    • CWE-770 - Allocation of Resources Without Limits or Throttling
    References
    Impacted products
    Vendor Product Version
    ZcashFoundation zebra Affected: < 4.4.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-44499",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-05-08T16:45:20.568414Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-08T17:23:27.910Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "zebra",
              "vendor": "ZcashFoundation",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003c 4.4.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra\u0027s block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems \u2014 all exercisable from a single TCP connection \u2014 to create a monotonically growing block deficit that never self-heals. This issue has been patched in version 4.4.0."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770: Allocation of Resources Without Limits or Throttling",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-08T15:11:24.837Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-h9hm-m2xj-4rq9",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-h9hm-m2xj-4rq9"
            }
          ],
          "source": {
            "advisory": "GHSA-h9hm-m2xj-4rq9",
            "discovery": "UNKNOWN"
          },
          "title": "ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-44499",
        "datePublished": "2026-05-08T15:11:24.837Z",
        "dateReserved": "2026-05-06T18:28:20.886Z",
        "dateUpdated": "2026-05-08T17:23:27.910Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }