VulnSea

zebrad vulnerabilities

CVEs whose affected-version data names the zebrad package (rust). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

14 CVEsRSS

CVE-2026-52736High
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the…

Twilightzebra-state · zebra-stateEPSS 0.44%via NVD
CVE-2026-52735Critical
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcod…

Midnightzebra-script · zebra-scriptEPSS 0.29%via NVD
CVE-2026-52737Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block w…

Sunlitzebra-consensus · zebra-consensusEPSS 0.20%via NVD
CVE-2026-52738Medium
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address can permanently halt Zebra nodes. In zebra-state/src/service/finalized_state/zebra_…

Sunlitzebra-state · zebra-stateEPSS 0.37%via NVD
CVE-2026-52739Medium· 5.9
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finali…

Sunlitzebra-state · zebra-stateEPSS 0.39%via NVD
CVE-2026-52733Medium· 6.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-commitment subtree roots in Zebra state. In zebra-state/src/service/non_finalized_state/…

Sunlitzebra-state · zebra-stateEPSS 0.34%via NVD
CVE-2026-52734Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/compo…

Sunlitzebrad · zebradEPSS 0.37%via NVD
CVE-2026-52829High· 7.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized …

Twilightzebra-network · zebra-networkEPSS 0.43%via NVD
CVE-2026-52731Medium· 6.5
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by supplying a getblocktemplate LongPollId containing multi-byte UTF-8 characters. In zebra-r…

Sunlitzebra-rpc · zebra-rpcEPSS 0.38%via NVD
CVE-2026-52732Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/memp…

Sunlitzebrad · zebradEPSS 0.37%via NVD
CVE-2026-54496Critical· 9.3
2mo ago

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Midnightzebrad · zebradEPSS 0.32%via GHSA
GHSA-h72h-ppcx-998pLow· 3.7
2mo ago

Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length

Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length

Sunlitzebra-network · zebra-networkvia GHSA
GHSA-443g-gwgp-49x4Low· 3.7
2mo ago

zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length

zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length

Sunlitzebrad · zebradvia GHSA
GHSA-c8w6-x74f-vmg3Medium· 6.5
2mo ago

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

Sunlitzebra-rpc · zebra-rpcvia GHSA
zebrad vulnerabilities (CVEs) · VulnSea