CVE-2026-104437: Zcashfoundation Zebra
High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Affected products
- Zcashfoundation Zebra: before 4.4.0 (fixed in 4.4.0)
Published 2026-10-02. Last modified 2026-10-06.