๐Ÿ” CVE Alert

CVE-2026-34377

UNKNOWN 0.0

Zebra has a Consensus Failure due to Improper Verification of V5 Transactions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1.

CWE CWE-347
Vendor zcashfoundation
Product zebra
Published Mar 31, 2026
Last Updated Mar 31, 2026
Stay Ahead of the Next One

Get instant alerts for zcashfoundation zebra

Be the first to know when new unknown vulnerabilities affecting zcashfoundation zebra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ZcashFoundation / zebra
< 4.3.0
ZcashFoundation / zebra-consensus
< 5.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-3vmh-33xr-9cqh github.com: https://github.com/ZcashFoundation/zebra/releases/tag/v4.3.0 zfnd.org: https://zfnd.org/zebra-4-3-0-critical-security-fixes-zip-235-support-and-performance-improvements