CVE-2026-104435
Received Received - Intake

ZIP-244 Consensus Rule Bypass in Zebra Zebrad

Vulnerability report for CVE-2026-104435, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
zebra zebrad to 4.4.1 (exc)
zebra zebrad 6.0.0
zebra zebra-script 6.0.0
zebra zebrad 4.4.0
zebra zebra_script 6.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zebra 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule for V5 transparent transactions. They accept transactions signed with SIGHASH_SINGLE that lack a matching output, causing Zebra to validate them while zcashd rejects them. This creates a network consensus split.

Detection Guidance

Check Zebra version with zebrad --version. Monitor network for transactions with V5 transparent inputs signed with SIGHASH_SINGLE lacking matching outputs. Compare transaction acceptance between Zebra and zcashd nodes.

Impact Analysis

An attacker could exploit this to broadcast crafted transactions that Zebra accepts but zcashd rejects. This may cause network partitioning, service disruption, or double-spend attacks. Users running affected Zebra versions risk network instability and potential financial losses.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to blockchain consensus mechanisms rather than data protection or privacy requirements. The issue involves a network consensus split due to improper transaction validation, which could disrupt service availability but does not inherently violate regulatory frameworks like GDPR or HIPAA.

Mitigation Strategies

Upgrade Zebra to version 4.4.1 or later immediately. Ensure all nodes run the patched version to prevent consensus divergence and potential network splits.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104435. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart