# CVE-2026-34377

## Summary

- **CVE ID:** CVE-2026-34377
- **Severity:** HIGH
- **CVSS Score:** 8.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H)
- **CWE:** CWE-347
- **Published:** Mar 31, 2026
- **Last Modified:** Mar 31, 2026

## Description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1.

## Affected Products

- ZcashFoundation — zebra (< 4.3.0)
- ZcashFoundation — zebra-consensus (< 5.0.1)

## References

- [CNA](https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-3vmh-33xr-9cqh)
- [CNA](https://github.com/ZcashFoundation/zebra/releases/tag/v4.3.0)
- [CNA](https://zfnd.org/zebra-4-3-0-critical-security-fixes-zip-235-support-and-performance-improvements)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._