zebra-network
crates.io3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zebra-networkpage 1 of 1
- CVE-2026-40881HIGHCVSS 7.5EG 7.5✓ Fixed in 5.0.12026-04-21
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maxim…
- CVE-2026-44500MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.0.02026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against gen…
- CVE-2026-52829HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.02026-07-02
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node listens on the default `[::]` address on a Linux host (the standa…
Check whether zebra-network is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zebra-network CVEs against the assets you own.
Start Free Scan →