---
id: CVE-2026-104434
title: >-
  ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a
  reachable assertion in the z_listunifiedreceivers RPC handler, which calls
  expect() on Sapling receiver parsing that fails for Unified Addresses carrying
  inva…
summary: >-
  ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a
  reachable assertion in the z_listunifiedreceivers RPC handler, which calls
  expect() on Sapling receiver parsing that fails for Unified Addresses carrying
  inva…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-617
vendor: ZcashFoundation
product: zebra
affected:
  - zebra < 8.0.0
  - zebra < 4.5.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T12:17:13.917'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104434'
references:
  - url: >-
      https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-c8w6-x74f-vmg3
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/zebra-before-8.0.0-denial-of-service-via-z-listunifiedreceivers-rpc
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T12:17:44.334Z'
---

## Overview

ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort the zebrad process, repeatably keeping the node offline.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
