ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1.
Metrics
Affected Vendors & Products
References
History
Mon, 06 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zfnd
Zfnd zebra Zfnd zebra-consensus |
|
| CPEs | cpe:2.3:a:zfnd:zebra-consensus:*:*:*:*:*:rust:*:* cpe:2.3:a:zfnd:zebra:*:*:*:*:*:rust:*:* |
|
| Vendors & Products |
Zfnd
Zfnd zebra Zfnd zebra-consensus |
|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zcashfoundation
Zcashfoundation zebra Zcashfoundation zebra-consensus |
|
| Vendors & Products |
Zcashfoundation
Zcashfoundation zebra Zcashfoundation zebra-consensus |
Tue, 31 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1. | |
| Title | Zebra has a Consensus Failure due to Improper Verification of V5 Transactions | |
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-31T14:05:59.959Z
Updated: 2026-03-31T17:18:12.932Z
Reserved: 2026-03-27T13:43:14.370Z
Link: CVE-2026-34377
Updated: 2026-03-31T17:18:09.921Z
Status : Analyzed
Published: 2026-03-31T15:16:19.233
Modified: 2026-04-06T16:57:21.713
Link: CVE-2026-34377
No data.