zebra-script
crates.io4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting zebra-scriptpage 1 of 1
- CVE-2026-104435HIGHCVSS 7.4EG 7.4fixed in 6.0.12026-10-02
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inpu…
- CVE-2026-41583CRITICALCVSS 9.1EG 9.1fixed in 5.0.22026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types…
- CVE-2026-44497CRITICALCVSS 9.1EG 9.1fixed in 6.0.02026-05-08
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash …
- CVE-2026-52735CRITICALCVSS 9.3EG 9.3fixed in 7.0.02026-07-02
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcodes…
Check whether zebra-script is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for zebra-script CVEs against the assets you own.
Book a Demo →