CVE-2026-104435
Received
Received - Intake
ZIP-244 Consensus Rule Bypass in Zebra Zebrad
Vulnerability report for CVE-2026-104435, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-02
Last updated on: 2026-10-02
Assigner: VulnCheck
Description
Description
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zebra | zebrad | to 4.4.1 (exc) |
| zebra | zebrad | 6.0.0 |
| zebra | zebra-script | 6.0.0 |
| zebra | zebrad | 4.4.0 |
| zebra | zebra_script | 6.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |