CRITICAL🇵🇱 Wersja polska

CVE-2026-41584

CVSS 9.2v4.0pub. 2026-05-08

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" value), however, the orchard crate which is used to verify Orchard proofs would panic when fed a rk with the identity value. Thus an attacker could send a crafted transaction that would make a Zebra node crash. This issue has been patched in zebrad version 4.3.1 and zebra-chain version 6.0.2.

🤖 AI Analysis
How it works

Orchard transactions contain an rk field, which is a random validation key and elliptic curve point. The Zcash specification allows the rk field to take an identity value (so-called zero value). However, the orchard library used by Zebra to verify Orchard proofs triggers a panic in Rust when it receives an rk field with an identity value. An attacker can thus send a specially crafted transaction containing such a value to the network, resulting in an immediate node crash.

Impact

An attacker can remotely cause a Zebra node to crash (denial of service), preventing its further operation. If the node is restarted multiple times without applying a patch, an attacker can maintain it in a continuous state of unavailability.

Mitigation & patch

Update zebrad to version 4.3.1 or later and zebra-chain to version 6.0.2 or later. Details are available in the official Zebra project security advisory on GitHub.

Who is affected

zebrad in versions earlier than 4.3.1 and zebra-chain in versions earlier than 6.0.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Zfnd Zebra Chain

    APP
    Zfnd
    < 6.0.2
  • Zfnd Zebrad

    APP
    Zfnd
    < 4.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-44497CRITICAL9.3PL ✓same product

Nieprawidłowa weryfikacja sygnatury w węźle ZEBRA (Zcash) — ryzyko rozszczepienia konsensusu

CVE-2026-44498CRITICAL9.2PL ✓same product

Błędne zliczanie sigops w Zebra powoduje split sieci Zcash

CVE-2026-41583CRITICAL9.3PL ✓same product

Błąd walidacji sighash w Zebra — możliwy consensus split z zcashd

CVE-2026-34202CRITICAL9.2PL ✓same product

Zdalne wywołanie paniki węzła Zebra przez spreparowaną transakcję V5

CVE-2026-40880HIGH7.2same product

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0....