zebra是Zcash Foundation开源的一个用Rust编写的Zcash全节点实现。 zebra 2.2.0版本至4.3.1之前版本存在安全漏洞,该漏洞源于JSON-RPC HTTP中间件在请求体未完全接收时断开连接,可能导致节点崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZcashFoundation | zebra | zebra-rpc >= 1.0.0-beta.45, < 6.0.2 |
affected |
zebrad >= 2.2.0, < 4.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZcashFoundation | zebra | zebra-rpc >= 1.0.0-beta.45, < 6.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44500 | 5.3 MEDIUM | ZEBRA: Allocation Amplification in Inbound Network Deserializers |
| CVE-2026-41583 | ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling | |
| CVE-2026-41584 | ZEBRA: rk Identity Point Panic in Transaction Verification | |
| CVE-2026-44497 | ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer | |
| CVE-2026-44498 | ZEBRA: Block Validator Undercounts Coinbase and P2SH Sigops | |
| CVE-2026-44499 | ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning |
No comments yet