CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-34202

CVSS 9.2v4.0pub. 2026-03-31upd. 2026-07-24

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation. This issue has been patched in zebrad version 4.3.0 and zebra-chain version 6.0.1.

🤖 AI Analysis
How it works

An attacker sends a specially crafted V5 transaction that successfully passes the initial deserialization stage but subsequently causes a critical error during the calculation of the transaction ID. Improper handling of this error state results in process panic and immediate node shutdown. The vulnerability stems from a combination of vulnerable deserialization (CWE-502) and errors in the logic for calculating values derived from input data (CWE-94, CWE-1336).

Impact

An attacker can remotely and without authentication cause multiple failures of the Zebra node, leading to service unavailability (DoS) at both the node level and dependent systems. This results in the inability of the node to participate in the Zcash network.

Mitigation & patch

Update zebrad to version 4.3.0 or later and zebra-chain to version 6.0.1 or later. Patches are available in the official ZcashFoundation GitHub repository (https://github.com/ZcashFoundation/zebra/releases/tag/v4.3.0).

Who is affected

zebrad in versions prior to 4.3.0 and zebra-chain in versions prior to 6.0.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Zfnd Zebra

    APP
    Zfnd
    < 4.3.0
  • Zfnd Zebra Chain

    APP
    Zfnd
    < 6.0.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth BypassDeserialization
CWE
References

Related vulnerabilities

CVE-2026-41584CRITICAL9.2PL ✓same product

Crash węzła Zebra (Zcash) przez pole rk z wartością tożsamości w transakcjach Orchard

CVE-2026-34377HIGH8.4same product

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0....

CVE-2026-44500MEDIUM5.3same product

ZEBRA to węzeł Zcash napisany całkowicie w Rust. Przed wersją zebrad 4.4.0, zebra-chain 7.0.0 i zebra-network ...

CVE-2026-41583CRITICAL9.3PL ✓same vendor

Błąd walidacji sighash w Zebra — możliwy consensus split z zcashd

CVE-2026-44497CRITICAL9.3PL ✓same vendor

Nieprawidłowa weryfikacja sygnatury w węźle ZEBRA (Zcash) — ryzyko rozszczepienia konsensusu