ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling
Published May 8, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.47%
Description
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes could thus accept and eventually mine a block that would be considered invalid by zcashd nodes, creating a consensus split between Zebra and zcashd nodes. In a similar vein, for V4 transactions, Zebra mistakenly used the "canonical" hash type when computing the sighash while zcashd (correctly per the spec) uses the raw value, which could also crate a consensus split. This issue has been patched in zebrad version 4.3.1 and zebra-script version 5.0.2.
Affected products
-
- Version zebra-script < 5.0.2StatusaffectedConstraints-
- Version zebrad < 4.3.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ZcashFoundation | Zebra | n/a |
|
- < 5.0.2
- < 4.3.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28653 Advisory
- https://github.com/ZcashFoundation/zebra/commit/1f605eca5c55e3b65229fa01a97d9aa84fd37447
- https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-8m29-fpq5-89jj x_refsource_CONFIRMVendor Advisory
- https://github.com/advisories/GHSA-8m29-fpq5-89jj Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41583
Change history (0)
No recorded changes yet.