Ad

CVE-2026-34377

HIGH CVSS 4.0: 8.4 EPSS 0.02%
Updated Apr 06, 2026
Zebra
Parameter Value
CVSS 8.4 (HIGH)
Affected Versions before 5.0.1
Fixed In 4.3.0
Type CWE-347 (Improper Verification of Cryptographic Signature)
Vendor Zebra
Public PoC No

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network.

This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Zfnd Zebra
cpe:2.3:a:zfnd:zebra:*:*:*:*:*:rust:*:*
4.3.0
Zfnd Zebra-Consensus
cpe:2.3:a:zfnd:zebra-consensus:*:*:*:*:*:rust:*:*
5.0.1

Related Vulnerabilities