CVE-2026-104437 PUBLISHED

Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling

Assigner: VulnCheck
Reserved: 02.10.2026 Published: 02.10.2026 Updated: 02.10.2026

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.3

Product Status

Vendor ZcashFoundation
Product zebra
Versions Default: unaffected
  • affected from 0 to 4.4.0 (excl.)
  • Version 4.4.0 is unaffected

Credits

  • sangsoo-osec reporter
  • defuse reporter
  • mpguerra coordinator
  • upbqdn finder

References

Problem Types

  • Improper Verification of Cryptographic Signature CWE