Sceawere
Vulnerability Detail
CVE-2026-104435UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zebra ZIP-244 Consensus Rule Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 11h ago
- Vendor
- ZcashFoundation
- Product
- zebra
- Attack Type
- Improper Verification of Cryptographic Signature
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-10-02T12:17:14.063Z",
"pubdate": "2026-10-02T12:17:14.063Z",
"executiveSummary": "This vulnerability involves a critical consensus failure in Zebra 4.4.0 and zebra-script 6.0.0 concerning the validation of V5 transparent inputs. The flaw arises from a failure to enforce the ZIP-244 consensus rule, which dictates the structural requirements for transactions using SIGHASH_SINGLE.\nSpecifically, the affected software incorrectly validates V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding index-matched output. This discrepancy causes Zebra to accept malformed transactions that are strictly rejected by zcashd.\nThe primary impact is a network consensus split, where Zebra-based nodes diverge from the canonical blockchain state maintained by zcashd nodes. This divergence undermines the integrity of the Zcash network, as malicious actors can broadcast crafted transactions to induce chain forks. The exploitation requires no specific authentication or elevated privileges, as it targets the transaction validation logic of the peer-to-peer network layer. By broadcasting transactions that pass Zebra's validation but fail global consensus rules, attackers can disrupt network synchronization and potentially facilitate double-spend attempts or partition the network between Zebra and zcashd implementations.",
"technicalDetails": "The root cause of this vulnerability is an incomplete implementation of the ZIP-244 consensus rule within the transaction validation logic of Zebra 4.4.0 and zebra-script 6.0.0. ZIP-244 specifies that for V5 transparent transactions utilizing the SIGHASH_SINGLE signature hash type, there must be a valid, index-matched output corresponding to the input index.\nWhen a transaction input specifies SIGHASH_SINGLE, the signature covers the input and exactly one corresponding output at the same index. If the transaction contains fewer outputs than the input index requires, the ZIP-244 protocol dictates that the transaction must be considered invalid and rejected by consensus-compliant nodes.\nIn the affected versions of Zebra, the validation engine fails to verify the existence of the corresponding output index when processing SIGHASH_SINGLE signatures in V5 transactions. Consequently, the node accepts transactions where the number of inputs exceeds the number of available outputs, a state explicitly prohibited by the protocol specification.\nThe attack flow proceeds as follows: 1) An attacker constructs a malicious V5 transparent transaction containing multiple inputs, where at least one input uses the SIGHASH_SINGLE flag. 2) The attacker deliberately omits the required output at the corresponding index, violating ZIP-244. 3) The attacker broadcasts this transaction to the network. 4) Zebra nodes validate the transaction locally, fail to detect the ZIP-244 violation, and incorporate the transaction into their mempool and subsequent blocks. 5) zcashd nodes receive the same transaction, identify the consensus violation, and reject it as invalid.\nThis divergence results in a network split. Because Zebra nodes operate on a different ledger state than the zcashd majority, they will reject blocks produced by zcashd that follow the correct protocol, or produce blocks that zcashd rejects. This causes a permanent fork between the two implementations, disrupting the global consensus mechanism. The vulnerability is triggered automatically upon transaction processing and requires no prior network state or authentication. The post-exploitation impact includes the inability for Zebra nodes to participate in the canonical Zcash chain, potential denial-of-service on the affected software, and the risk of successful double-spending against merchants or services relying solely on Zebra nodes for transaction confirmation."
}