Sceawere

Vulnerability Detail

CVE-2026-104430UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebra Consensus Signature Counting Divergence

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Function Call with Incorrectly Specified Arguments
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-02T12:17:13.467Z",
  "pubdate": "2026-10-02T12:17:13.467Z",
  "executiveSummary": "Zebra (zebrad version 4.5.0 and zebra-script version 7.0.0) exhibits a critical consensus divergence vulnerability stemming from incorrect P2SH (Pay-to-Script-Hash) signature operation (sigop) counting. Unlike zcashd, which employs an accurate P2SH sigop counting mechanism, Zebra utilizes a legacy-mode heuristic that incorrectly classifies CHECKMULTISIG operations preceded by OP_1 through OP_16 as incurring a cost of 20 sigops.\nThis overcounting leads to a state where a block deemed valid by zcashd is rejected by Zebra nodes due to an inflated MAX_BLOCK_SIGOPS calculation. An attacker can exploit this by crafting and broadcasting P2SH transactions utilizing low-threshold multisig scripts. By purposefully exceeding Zebra's inflated limit while remaining under zcashd's limit, an attacker can induce a consensus failure, forcing Zebra nodes to stall and disconnect from the canonical chain. This represents a significant availability risk to the Zebra implementation within the Zcash network, as it allows remote adversaries to effectively partition Zebra nodes from the network by forcing them into an invalid state based on false consensus violations.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of the script evaluation engine within zebra-script version 7.0.0. When processing P2SH redeem scripts, the engine fails to implement the specific sigop counting logic required by the Zcash consensus rules, which differs from legacy Bitcoin implementations. Specifically, while zcashd correctly interprets and counts signature operations within P2SH scripts, Zebra reverts to a legacy-style evaluation mode.\nIn this legacy mode, the Zebra engine incorrectly identifies OP_CHECKMULTISIG opcodes that are preceded by OP_1 through OP_16. Instead of counting these operations based on their actual multisig thresholds as specified in the consensus rules, Zebra assigns a static cost of 20 sigops to these instances. This results in an artificial inflation of the total signature operations counted for a given block.\nThe exploitation flow is as follows: 1) An attacker constructs a transaction using a P2SH multisig redeem script where the multisig threshold is low, but the total number of public keys involved is manipulated to trigger the faulty sigop counting logic in Zebra. 2) The attacker broadcasts this transaction within a block or as a standalone transaction that gets included in a block. 3) Upon receipt, zcashd validates the block correctly, confirming the sigop count is within the network-defined MAX_BLOCK_SIGOPS limits. 4) The Zebra node, upon processing the same block, applies its incorrect legacy counting heuristic, resulting in a calculated sigop count that exceeds the MAX_BLOCK_SIGOPS limit. 5) Consequently, the Zebra node marks the block as invalid due to a consensus violation and rejects it.\nThe impact is a deterministic chain stall. Since Zebra nodes will reject blocks that are accepted by the wider zcashd network, the affected nodes lose synchronization with the blockchain. Because the network depends on consistent consensus rules, this divergence prevents Zebra from tracking the canonical chain, effectively resulting in a denial-of-service on the affected node's ability to participate in the network. No authentication or privileged access is required to exploit this, as the attack is performed by simply broadcasting standard (though specifically crafted) transactions onto the public P2P network."
}
CVE-2026-104430: Zebra Consensus Signature Counting Divergence (HIGH Severity, CVSS: 7.5) | Sceawere