๐Ÿ” CVE Alert

CVE-2026-104430

HIGH 7.5

Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.

CWE CWE-628
Vendor zcashfoundation
Product zebra
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for zcashfoundation zebra

Be the first to know when new high vulnerabilities affecting zcashfoundation zebra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

ZcashFoundation / zebra
4.5.0 < 4.5.1
ZcashFoundation / zebra
7.0.0 < 7.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2prc-cj5x-4443 vulncheck.com: https://www.vulncheck.com/advisories/zebra-4.5.0-consensus-split-via-p2sh-sigop-overcount

Credits

๐Ÿ” sangsoo-osec