CVE-2026-41583
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes could thus accept and eventually mine a block that would be considered invalid by zcashd nodes, creating a consensus split between Zebra and zcashd nodes. In a similar vein, for V4 transactions, Zebra mistakenly used the "canonical" hash type when computing the sighash while zcashd (correctly per the spec) uses the raw value, which could also crate a consensus split. This issue has been patched in zebrad version 4.3.1 and zebra-script version 5.0.2.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
- EPSS probability
- 0.28%
- CWE
- CWE-573
- Published
- 2026-05-08
- Last modified
- 2026-05-08
Affected products
- ZcashFoundation zebra
- ZcashFoundation zebra
Weakness type
Related vulnerabilities
- CVE-2026-59998 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior:...
- CVE-2026-28498 — Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
- CVE-2025-69287 — BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability
- CVE-2025-69202 — axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
- CVE-2025-46330 — Snowflake Connector for C/C++ retries malformed requests
- CVE-2019-14829 — A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier...