CVE-2026-104435: Zcashfoundation Zebra
High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Affected products
- Zcashfoundation Zebra: from 4.4.0, before 4.4.1 (fixed in 4.4.1); from 6.0.0, before 6.0.1 (fixed in 6.0.1)
Published 2026-10-02. Last modified 2026-10-02.