-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0224 ============================================================ Advisory-ID: 0xCERT-2026-0224 Severity: High Published: 2026-03-30T19:13:41.000Z Updated: 2026-10-08T22:48:27.839Z Chains: n/a URL: https://www.0xcert.com/advisory/0xCERT-2026-0224 Title: Zebra has a Consensus Failure due to Improper Verification of V5 Transactions Summary - ------- Zebra has a Consensus Failure due to Improper Verification of V5 Transactions. --- A logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. Details - ------- Summary - --- A logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. Affected - - zebrad (rust) < 4.3.0 — fixed in 4.3.0 - - zebra-consensus (rust) < 5.0.1 — fixed in 5.0.1 Severity High (CVSS 8.4), as rated by the upstream advisory. Recommended actions - - Upgrade zebrad to 4.3.0 or later - - Upgrade zebra-consensus to 5.0.1 or later Source & attribution This 0xCERT advisory summarises GHSA-3vmh-33xr-9cqh / CVE-2026-34377 from the GitHub Advisory Database, credited upstream to conradoplg, mpguerra, alchemydc: https://github.com/advisories/GHSA-3vmh-33xr-9cqh. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/advisories/GHSA-3vmh-33xr-9cqh - - CVE-2026-34377 - - https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-3vmh-33xr-9cqh - - https://zfnd.org/zebra-4-3-0-critical-security-fixes-zip-235-support-and-performance-improvements - - https://zips.z.cash/zip-0244 - - https://nvd.nist.gov/vuln/detail/CVE-2026-34377 - - https://github.com/ZcashFoundation/zebra/releases/tag/v4.3.0 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrI9YwJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmfNp3ZgJZHU6x5yeALUe8Dh+2CyHPdr9rdl4pfs H8uljxYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAABNcQD/QvuPAfZPvh3RXdvY SScfRqFrO5Rqbg97oMec8K+jJWQBAIRIa9bzSRg1vgIuohTeYdOXptHxm+w9 rLs7mqBztkMG =9U3G -----END PGP SIGNATURE-----