-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 0xCERT Security Advisory 0xCERT-2026-0226 ============================================================ Advisory-ID: 0xCERT-2026-0226 Severity: High Published: 2026-04-18T00:41:54.000Z Updated: 2026-10-08T22:48:28.412Z Chains: n/a URL: https://www.0xcert.com/advisory/0xCERT-2026-0226 Title: Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks Summary - ------- Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks. A logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. Details - ------- Summary A logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. Affected - - zebra-consensus (rust) < 5.0.2 — fixed in 5.0.2 - - zebrad (rust) < 4.3.1 — fixed in 4.3.1 Severity High (CVSS 7.2), as rated by the upstream advisory. Recommended actions - - Upgrade zebra-consensus to 5.0.2 or later - - Upgrade zebrad to 4.3.1 or later Source & attribution This 0xCERT advisory summarises GHSA-xvj8-ph7x-65gf / CVE-2026-40880 from the GitHub Advisory Database, credited upstream to sangsoo-osec, conradoplg, mpguerra: https://github.com/advisories/GHSA-xvj8-ph7x-65gf. Details may change; refer to the original source for the authoritative record. References - ---------- - - https://github.com/advisories/GHSA-xvj8-ph7x-65gf - - CVE-2026-40880 - - https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-xvj8-ph7x-65gf - - https://nvd.nist.gov/vuln/detail/CVE-2026-40880 Verify with the 0xCERT OpenPGP key: https://www.0xcert.com/pgp.asc Fingerprint: 5F94 3ED1 1E50 CF31 2128 C493 CCC7 D9EC 9415 723D -----BEGIN PGP SIGNATURE----- wrsEARYKAG0FgmrISDAJEDe9Tbcr+ZxrRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmc/5HXNjKA4EXhZxQfcJg5W7Sy7knDBmDQa1VJ0 gW1I1RYhBGCkkFZbJcT5QWu27ze9Tbcr+ZxrAABclAD/TwoaufiHfNNQAlgu PqZUbmsDKIZH/T4RyxehZcDMD0gA/2+J/aL/Fcr9y4HBx1bXg+y0EKlCC+Fy SOXQkCM4dggA =Xwd6 -----END PGP SIGNATURE-----