CVE-2026-34377 Details
Description
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1.
A consensus split vulnerability has been identified in ZEBRA, a Zcash node implementation in Rust, affecting versions prior to ZEBRA 4.3.0 and zebra-consensus 5.0.1. The issue arises from a logic error in the transaction verification cache, which could allow a malicious miner to induce a consensus split by matching a valid transaction's txid while providing invalid authorization data. This would lead vulnerable ZEBRA nodes to accept invalid blocks, causing a split from the Zcash network. While invalid transactions themselves would not be accepted, the vulnerability could create a rift between affected ZEBRA nodes and those running Zcashd or the patched ZEBRA version.
Users should upgrade to ZEBRA version 4.3.0 or zebra-consensus version 5.0.1. Instructions for upgrading are available on the Zcash Foundation's GitHub page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zfnd zebra | < 4.3.0 |
CPE
Remediation
| |
| zfnd zebra-consensus | < 5.0.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | [email protected] |