zebrad
crates.io22 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zebradpage 1 of 1
- CVE-2026-34202HIGHCVSS 7.5EG 7.5✓ Fixed in 4.3.02026-03-31
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (…
- CVE-2026-34377HIGHCVSS 8.1EG 8.1✓ Fixed in 4.3.02026-03-31
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching…
- CVE-2026-40880HIGHCVSS 8.1EG 8.1✓ Fixed in 4.3.12026-04-21
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefull…
- CVE-2026-40881HIGHCVSS 7.5EG 7.5✓ Fixed in 4.3.12026-04-21
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maxim…
- CVE-2026-41583CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.3.12026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types…
- CVE-2026-41584HIGHCVSS 7.5EG 7.5✓ Fixed in 4.3.12026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash …
- CVE-2026-41585MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.3.12026-05-08
ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to…
- CVE-2026-44497CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.4.02026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash …
- CVE-2026-44498HIGHCVSS 7.5EG 7.5✓ Fixed in 4.4.02026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd r…
- CVE-2026-44499HIGHCVSS 8.7EG 8.7✓ Fixed in 4.4.02026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery o…
- CVE-2026-44500MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.4.02026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against gen…
- CVE-2026-52731MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.5.02026-07-02
zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your `zebrad.toml` sets `rpc.listen_addr` to a TCP address (…
- CVE-2026-52732MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.5.02026-07-02
zebrad has mempool transaction admission denial via single-peer inbound queue saturation ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node accepts inbound P2P connections (`network.lis…
- CVE-2026-52733MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.5.02026-07-02
zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node participates in a network where…
- CVE-2026-52734MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.5.02026-07-02
zebrad has unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node accepts inbound P2P connection…
- CVE-2026-52735CRITICALEG 0.0✓ Fixed in 4.5.02026-07-02
zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser ### Am I affected You are affected if: 1. You run any version of `zebrad` up to and including `v4.4.1`. 2. Your node validates blocks on mainn…
- CVE-2026-52736HIGHEG 0.0✓ Fixed in 4.5.02026-07-02
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache ## Description ### Am I affected You are affected if: 1. You run any version of `zebrad` up to and including `v4.4.1`. 2. Your node accepts inbound P2P c…
- CVE-2026-52737MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.5.02026-07-02
Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node accepts inbound P2P connections and is syn…
- CVE-2026-52738MEDIUMEG 0.0✓ Fixed in 4.5.02026-07-02
Zebra: Finalized address balance credit-first overflow on consensus-valid blocks ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node processes blocks on any Zcash network. ### Summary …
- CVE-2026-52739MEDIUMCVSS 5.9EG 5.9✓ Fixed in 4.5.02026-07-02
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node processes blocks past the checkpo…
- CVE-2026-52829HIGHCVSS 7.5EG 7.5✓ Fixed in 4.5.02026-07-02
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update ### Am I affected You are affected if: 1. You run `zebrad` up to and including `v4.4.1`. 2. Your node listens on the default `[::]` address on a Linux host (the standa…
- CVE-2026-54496CRITICALCVSS 9.3EG 9.3✓ Fixed in 5.0.02026-07-06
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomp…
Check whether zebrad is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zebrad CVEs against the assets you own.
Start Free Scan →