CVE-2026-104435

Summary

Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.

Affected Software

VendorProductVersion RangeStatus
ZcashFoundationzebra4.4.0 < 4.4.1affected
ZcashFoundationzebra4.4.1unaffected
ZcashFoundationzebra6.0.0 < 6.0.1affected
ZcashFoundationzebra6.0.1unaffected

Weaknesses

  • CWE-347: Improper Verification of Cryptographic Signature

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References