Sceawere
Vulnerability Detail
CVE-2026-104437UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zebra V5 Signature Consensus Divergence
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 11h ago
- Vendor
- ZcashFoundation
- Product
- zebra
- Attack Type
- Improper Verification of Cryptographic Signature
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-10-02T12:17:14.357Z",
"pubdate": "2026-10-02T12:17:14.357Z",
"executiveSummary": "Zebra versions prior to 4.4.0 contain a consensus-critical vulnerability regarding the validation of V5 transparent signature inputs.\nThe vulnerability is characterized by a failure to strictly enforce ZIP-244 digest computation requirements for SIGHASH_SINGLE inputs when the associated transaction output index does not exist.\nUnder these conditions, Zebra incorrectly proceeds with block template construction instead of rejecting the transaction as invalid.\nThis behavior introduces a consensus divergence between Zebra and the zcashd reference implementation.\nAn attacker can exploit this flaw by crafting malicious V5 transactions that possess fewer outputs than inputs.\nBecause Zebra accepts these transactions into its mempool and includes them in blocks via getblocktemplate, the resulting blocks are rejected by zcashd nodes.\nThis discrepancy effectively allows for a denial-of-service vector against the network-wide consensus, as blocks mined by affected Zebra nodes will be invalidated by the rest of the ecosystem, leading to chain splits or total network synchronization failures.\nExploitation requires the ability to submit specifically malformed transactions that trigger the flawed signature verification logic within the Zebra transaction processing engine.",
"technicalDetails": "The vulnerability resides in the V5 transparent signature verification logic within the Zebra transaction processing component.\nIn Zcash V5 transactions, the signature hash (SIGHASH) calculation for transparent inputs is governed by ZIP-244, which defines how digests are computed to ensure transaction integrity.\nWhen a transaction uses SIGHASH_SINGLE, the signature commit mechanism expects a corresponding output at the same index as the input being signed.\nThe root cause of the vulnerability is an incomplete implementation of the ZIP-244 specification in Zebra. Specifically, the software fails to validate the existence of a corresponding output index when computing the digest for SIGHASH_SINGLE inputs.\nInstead of returning a validation failure when the output index is out of bounds, Zebra proceeds to compute an invalid ZIP-244 digest based on the available, insufficient data.\nThe attack flow proceeds as follows: First, the attacker crafts a V5 transaction where the number of transparent inputs exceeds the number of transparent outputs.\nSecond, the attacker sets the SIGHASH flag to SIGHASH_SINGLE for one or more inputs, pointing to an index that does not exist in the transaction's output list.\nThird, the malicious transaction is broadcast to a Zebra node. The node's transaction validation logic, due to the identified flaw, incorrectly marks the transaction as valid because it does not trigger the expected rejection criteria for missing output indices.\nFourth, the Zebra node includes this malformed transaction in a candidate block through the getblocktemplate RPC interface.\nFinally, when this block is broadcast to the network, nodes running zcashd—which correctly implements the ZIP-244 specification and rejects transactions where SIGHASH_SINGLE inputs refer to non-existent outputs—will identify the block as invalid.\nThis causes a consensus divergence, as the Zebra-mined block is rejected, effectively isolating the Zebra node and halting its participation in the canonical chain, while potentially causing chain stalls if multiple nodes rely on this flawed logic.\nThis issue represents a significant deviation from the Zcash network protocol, as the transaction structure violates the core consensus rules regarding input/output alignment for specific SIGHASH types."
}