Zfnd

Zebrad

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 08.05.2026 15:17:01
  • Zuletzt bearbeitet 08.05.2026 18:42:24

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is inv...

  • EPSS 0.28%
  • Veröffentlicht 08.05.2026 15:17:01
  • Zuletzt bearbeitet 08.05.2026 18:40:55

ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 08.05.2026 15:17:01
  • Zuletzt bearbeitet 08.05.2026 18:01:52

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transp...

  • EPSS 0.28%
  • Veröffentlicht 08.05.2026 15:16:41
  • Zuletzt bearbeitet 08.05.2026 18:44:58

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 tra...

  • EPSS 0.27%
  • Veröffentlicht 08.05.2026 15:16:41
  • Zuletzt bearbeitet 08.05.2026 18:21:13

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specificati...

  • EPSS 0.26%
  • Veröffentlicht 08.05.2026 15:16:41
  • Zuletzt bearbeitet 08.05.2026 18:19:56

ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Ze...

  • EPSS 0.26%
  • Veröffentlicht 21.04.2026 19:20:53
  • Zuletzt bearbeitet 27.04.2026 18:24:28

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (...

  • EPSS 0.26%
  • Veröffentlicht 21.04.2026 19:18:22
  • Zuletzt bearbeitet 27.04.2026 18:26:19

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submittin...