VYPR

crates.io package

zebrad

pkg:cargo/zebrad

Vulnerabilities (9)

  • CVE-2026-44500MedMay 8, 2026
    affected < 4.4.0fixed 4.4.0

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings bef

  • CVE-2026-44498HigMay 8, 2026
    affected < 4.4.0fixed 4.4.0

    ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who p

  • CVE-2026-44497CriMay 8, 2026
    affected < 4.4.0fixed 4.4.0

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computati

  • CVE-2026-41585MedMay 8, 2026
    affected >= 2.2.0, < 4.3.1fixed 4.3.1

    ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnec

  • CVE-2026-41584HigMay 8, 2026
    affected < 4.3.1fixed 4.3.1

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the

  • CVE-2026-41583CriMay 8, 2026
    affected < 4.3.1fixed 4.3.1

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled i

  • CVE-2026-40880HigApr 21, 2026
    affected < 4.3.1fixed 4.3.1

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid

  • CVE-2026-34377HigMar 31, 2026
    affected < 4.3.0fixed 4.3.0

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providi

  • CVE-2026-34202HigMar 31, 2026
    affected < 4.3.0fixed 4.3.0

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a sp