CVE-2026-104437

Summary

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

Affected Software

VendorProductVersion RangeStatus
ZcashFoundationzebra0 < 4.4.0affected
ZcashFoundationzebra4.4.0unaffected

Weaknesses

  • CWE-347: Improper Verification of Cryptographic Signature

References