zebra-consensus
crates.io3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zebra-consensuspage 1 of 1
- CVE-2026-34377HIGHCVSS 8.1EG 8.1✓ Fixed in 5.0.12026-03-31
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching…
- CVE-2026-40880HIGHCVSS 8.1EG 8.1✓ Fixed in 5.0.22026-04-21
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefull…
- CVE-2026-52737MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.0.02026-07-02
Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node accepts inbound P2P connections and is syn…
Check whether zebra-consensus is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zebra-consensus CVEs against the assets you own.
Start Free Scan →