zebra是Zcash Foundation开源的一个用Rust编写的Zcash全节点实现。 zebra 4.4.0之前版本存在安全漏洞,该漏洞源于区块验证器低估透明签名操作次数,可能导致网络分裂。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ZcashFoundation | zebra | < 4.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ZcashFoundation | zebra | < 4.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44500 | 5.3 MEDIUM | ZEBRA: Allocation Amplification in Inbound Network Deserializers |
| CVE-2026-41585 | ZEBRA: Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients | |
| CVE-2026-41583 | ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling | |
| CVE-2026-41584 | ZEBRA: rk Identity Point Panic in Transaction Verification | |
| CVE-2026-44497 | ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer | |
| CVE-2026-44499 | ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning |
No comments yet