CVE-2026-104430
Received Received - Intake

Zcash P2SH SigOp Overcounting in Zebra 4.5.0

Vulnerability report for CVE-2026-104430, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
zebra zebrad From 4.5.1 (exc)
zebra zebra_script From 7.0.1 (exc)
zebra zebrad 4.5.0
zebra zebra_script 7.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-628 The product calls a function, procedure, or routine with arguments that are not correctly specified, leading to always-incorrect behavior and resultant weaknesses.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104430 is a consensus split vulnerability in Zebra versions 4.5.0 and 7.0.0. It involves an incorrect counting of P2SH signature operations where Zebra uses a legacy mode that overcounts CHECKMULTISIG operations as 20 sigops instead of their actual count (1 to 16). This causes Zebra nodes to reject valid blocks that exceed their inflated MAX_BLOCK_SIGOPS limit, leading to chain stalls.

Detection Guidance

To detect this vulnerability, check the Zebra node version running on your system. If it is version 4.5.0 or 7.0.0, it is vulnerable. Use commands like 'zebrad --version' or 'zebra-script --version' to verify the installed version.

Impact Analysis

Remote attackers can exploit this by broadcasting P2SH spends with low-threshold multisig redeem scripts. This causes Zebra nodes to stall while the rest of the network advances, resulting in a chain split. Users running affected Zebra versions may experience network disruptions or inability to validate new blocks.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a technical consensus issue in the Zebra Zcash node software that could lead to chain stalls or splits, disrupting network integrity rather than data protection or privacy compliance.

Mitigation Strategies

Upgrade Zebra to version 4.5.1 or 7.0.1 or later immediately. This patch corrects the P2SH sigop counting issue and prevents consensus divergence. Follow the official Zebra upgrade instructions from the Zcash Foundation repository.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104430. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart