Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ZcashFoundation — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting ZcashFoundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The ZcashFoundation develops Zcash, a privacy-focused cryptocurrency using zero-knowledge proofs. Historically, its codebase has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, as evidenced by five disclosed CVEs. While no major security incidents have been publicly reported, the project's emphasis on privacy necessitates rigorous cryptographic assurance. The foundation maintains a bug bounty program to identify vulnerabilities, though the complexity of its privacy features presents ongoing security challenges. Regular audits and community scrutiny remain critical to maintaining trust in the network's integrity and user funds.

Found 38 results / 41 Clear Filters
Top products by ZcashFoundation: zebra zebrad frost
CVE ID Title CVSS Severity Published
CVE-2026-104437 Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling — zebra CWE-347 7.4 High 2026-10-02
CVE-2026-104436 Zebra before 4.5.0 CPU Amplification via Uncapped getblocks/getheaders Locator Length — zebra CWE-770 3.7 Low 2026-10-02
CVE-2026-104435 Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output — zebra CWE-347 7.4 High 2026-10-02
CVE-2026-104434 Zebra before 8.0.0 Denial of Service via z_listunifiedreceivers RPC — zebra CWE-617 6.5 Medium 2026-10-02
CVE-2026-104431 Zebra before 6.0.0 Denial of Service via Synchronous Script FFI Verification — zebra CWE-405 7.5 High 2026-10-02
CVE-2026-104432 Zebra before 6.3.0 False Readiness via Discarded One-Hash FindBlocks Response — zebra CWE-754 5.3 Medium 2026-10-02
CVE-2026-104430 Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount — zebra CWE-628 7.5 High 2026-10-02
CVE-2026-104428 Zebra before 11.0.0 Denial of Service via getblock Verbosity 2 — zebra CWE-617 5.3 Medium 2026-10-02
CVE-2026-104429 Zebra before 6.0.0-rc.0 Per-Peer Mempool Admission Bypass via P2P tx Messages — zebra CWE-770 5.3 Medium 2026-10-02
CVE-2026-104427 Zebra before 6.1.0 Chain Stall via Stale parent_error_map Entry — zebra CWE-459 5.9 Medium 2026-10-02
CVE-2026-104425 Zebra before 6.1.0 Batch-Verification Poisoning DoS via Unattributed Pushed Transactions — zebra CWE-405 5.3 Medium 2026-10-02
CVE-2026-104426 Zebra before 6.1.0 Quadratic Complexity DoS via Block Transparent Value Check — zebra CWE-407 5.9 Medium 2026-10-02
CVE-2026-104424 Zebra before 6.1.0 Incorrect Block Size Calculation in getblocktemplate — zebra CWE-131 3.7 Low 2026-10-02
CVE-2026-104423 Zebra before 6.2.1 Denial of Service via Uncapped V6 Shielded Proof Verification — zebra CWE-405 7.5 High 2026-10-02
CVE-2026-104422 Zebra before 6.3.0 Block Sync Denial of Service via Coinbase scriptSig Rewrite — zebra CWE-345 7.5 High 2026-10-02
CVE-2026-104420 Zebra before 6.3.0 Peer Misbehavior Ban Bypass via Gossiped Blocks — zebra CWE-704 5.3 Medium 2026-10-02
CVE-2026-104421 Zebra before 6.2.1 Block Download Denial of Service via KnownBlock SentHashes Lockout — zebra CWE-459 5.3 Medium 2026-10-02
CVE-2026-104419 Zebra before 6.3.0 Honest Peer Banning via Far-Ahead FindBlocks Hashes — zebra CWE-345 4.8 Medium 2026-10-02
CVE-2026-52829 ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book — zebra CWE-617 7.5 High 2026-08-18
CVE-2026-52736 ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache — zebra CWE-459 8.7 High 2026-08-18
CVE-2026-52732 ZEBRA: Mempool transaction admission denial via single-peer inbound queue saturation — zebra CWE-770 5.3 Medium 2026-08-18
CVE-2026-52731 ZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplate — zebra CWE-248 6.5 Medium 2026-08-18
CVE-2026-52733 ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip — zebra CWE-459 6.5 Medium 2026-08-18
CVE-2026-52738 ZEBRA: Finalized address balance credit-first overflow on consensus-valid blocks — zebra CWE-248 6.9 Medium 2026-08-18
CVE-2026-52735 ZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser — zebra CWE-684 9.3 Critical 2026-08-18
CVE-2026-52739 ZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection — zebra CWE-248 5.9 Medium 2026-08-18
CVE-2026-52734 ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention — zebra CWE-401 5.3 Medium 2026-08-18
CVE-2026-52737 ZEBRA: Sync restart poisoning from single unauthenticated peer via above-lookahead block — zebra CWE-345 5.3 Medium 2026-08-18
CVE-2026-54496 Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness — zebra CWE-345 9.3 Critical 2026-07-17
CVE-2026-44499 ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning — zebra CWE-770 7.5AI High AI 2026-05-08

This page lists every published CVE security advisory associated with ZcashFoundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.