CVE-2026-34377
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
- EPSS probability
- 0.26%
- CWE
- CWE-347
- Published
- 2026-03-31
- Last modified
- 2026-03-31
Affected products
- ZcashFoundation zebra
- ZcashFoundation zebra-consensus
Weakness type
Related vulnerabilities
- CVE-2026-48558 — SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification
- CVE-2026-33746 — Convoy: JWT Signature Verification Bypass Allows Authentication as Arbitrary Users
- CVE-2026-31946 — OpenOLAT: Authentication bypass via forged JWT in OIDC implicit flow
- CVE-2026-33026 — nginx-ui Backup Restore Allows Tampering with Encrypted Backups
- CVE-2026-4478 — Yi Technology YI Home Camera HTTP Firmware Update ipc signature verification
- CVE-2026-56451 — A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate
- CVE-2026-54782 — CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
- CVE-2026-5430 — Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover