High severity7.4NVD Advisory· Published Oct 2, 2026
CVE-2026-104435
CVE-2026-104435
Description
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Affected products
2- Range: 6.0.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.