CVE-2026-34202Disclosure(zfnd / zebra)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch zfnd zebra systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation. This issue has been patched in zebrad version 4.3.0 and zebra-chain version 6.0.1.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1336CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zebra
  • zebra-chain

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-30); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
zebrazebra-chain

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-29: 1Mentions · 2026-03-30: 3Mentions · 2026-03-31: 2PoC Mentioned / Linked · 2026-03-31: 1Patch / Workaround · 2026-03-30: 3Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 203-2903-3003-31
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-291
Disclosure1
2026-03-303
Patch3
2026-03-312
Disclosure2
Full discourse6 posts
  • robustfeng@robustdragon
    Patch

    Discovered a critical vulnerability in @ZcashFoundation's Zebra node (CVE-2026-34202) through coverage-guided fuzzing. Huge respect to the Zebra team for their rapid response — from disclosure to patched release in record time. This is how open-source security should work. 🤝 The latest Zebra version is now live with the fix. If you're running a Zcash node, please update. #zec #Zcash #Security #CVE #Rust #Fuzzing

    Post summary

    The post announces that a critical vulnerability (CVE‑2026‑34202) was found in the Zebra node, the issue was quickly patched, and users are urged to install the latest version.

    3605483.0K
    197 followersView on X
  • robustfeng@robustdragon
    Patch

    通过覆盖率引导模糊测试(coverage-guided fuzzing),我在 Zcash Foundation 的 Zebra 节点中发现了一个关键漏洞(CVE-2026-34202)。 感谢 Zebra 团队的快速响应,从漏洞披露到修复发布在极短时间内完成,这也是开源安全协作应有的样子。 当前版本已完成修复,如果你正在运行 Zcash 节点,请尽快升级。 #ZEC #Zcash #安全 #Rust #Fuzzing

    Post summary

    The post announces the rapid discovery and patch of CVE-2026-34202 in Zebra, urging users to upgrade.

    00030335
    197 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34202 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic a… https://www.cve.org/CVERecord?id=CVE-2026-34202

    Post summary

    The advisory discloses a transaction‑processing flaw in earlier Zebra releases, fixed in zebrad 4.3.0 and zebra‑chain 6.0.1.

    0000088
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34202: Zebra node crash — V5 transactio... Malformed V5 transactions can remotely nuke Zcash nodes through panic-inducing txid calculations—network-wide DoS poten... https://zerodaysignal.com/vulnerability/CVE-2026-34202 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑34202, a DoS vulnerability in Zcash’s Zebra node that can be triggered by malformed V5 transactions, and links to a page for more information.

    0000076
    194 followersView on X
  • Psychic Lab Ape@psyciclabs
    Patch

    CVE-2026-34202 CVSS 8.6 HIGH — crafted V5 tx passes deserialization but panics during tx ID calculation in Zcash Zebra. P2P-reachable, unauthenticated, zero-click DoS. All Zebra < v6.0.1 affected. Upgrade immediately — sole consensus node post-NU7. #zcash #infosec

    Post summary

    The post advertises a high‑severity CVE affecting Zebra nodes older than v6.0.1, provides mitigation instructions to upgrade, and supplies technical details but no evidence of active exploitation or PoC.

    000006
    19 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A `Zebra node` crash (CVE-2026-34202) is caused by a V5 transaction hash panic, reachable via P2P. This could lead to service disruption. #InfoSec #Vulnerability #CVE https://www.pulsepatch.io/posts/cve-2026-34202-zebra-node-crash-panic

    Post summary

    The tweet announces a new crash vulnerability (CVE‑2026‑34202) in Zebra nodes caused by a P2P‑reachable V5 transaction hash panic, but does not report exploits, patches, or active attacks.

    0000049
    6 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appzfndzebra-rust-
Appzfndzebra-chain-rust-

Explore more