CVE-2026-104437
Received Received - Intake

Zebra Consensus Divergence in V5 Signature Verification

Vulnerability report for CVE-2026-104437, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: VulnCheck

Description

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zebra zebra to 4.4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a consensus divergence issue between Zebra and zcashd in handling transparent SIGHASH_SINGLE transactions for Zcash version 5 and later. Zebra incorrectly computes a digest for missing outputs instead of rejecting invalid transactions, while zcashd rejects them. This creates a split where Zebra may accept and mine invalid transactions that zcashd later rejects.

Detection Guidance

To detect this vulnerability, monitor Zebra nodes for transactions with fewer transparent outputs than inputs, particularly those using SIGHASH_SINGLE signatures. Check if Zebra accepts such transactions while zcashd rejects them. Compare block templates generated by Zebra with those accepted by zcashd for discrepancies.

Impact Analysis

Attackers can exploit this to craft malicious transactions with fewer outputs than inputs. Zebra may include these in blocks via getblocktemplate, causing consensus failures. Zebra block-template producers face safety risks, and the network may split if nodes disagree on transaction validity.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to a consensus divergence in blockchain transaction validation rather than data protection or privacy controls. The issue involves a technical flaw in transaction handling that could lead to network splits or invalid blocks, but it does not inherently violate regulatory requirements for data security or privacy.

Mitigation Strategies

Upgrade Zebra to version 4.4.0 or later to address the consensus divergence. Ensure all nodes in the network run the patched version. Monitor for any blocks or transactions that cause consensus splits between Zebra and zcashd.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart