CVE-2026-34377Disclosure(zfnd / zebra)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zfnd zebra systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By matching a valid transaction's txid while providing invalid authorization data, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This would not allow invalid transactions to be accepted but could result in a consensus split between vulnerable Zebra nodes and invulnerable Zebra and Zcashd nodes. This issue has been patched in zebrad version 4.3.0 and zebra-consensus version 5.0.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zebra
  • zebra-consensus

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-31); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
zebrazebra-consensus

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-31: 2Mentions · 2026-06-03: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-03-31: 1Technical Details · 2026-06-03: 103-3106-03
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure1General1
2026-06-031
Patch1
Full discourse3 posts
  • Exitnode_@exitnode_
    Patch

    I genuinely do not get the psyop around Zcash. This guy tries to reference "moneros inflation bug" which hasnt happened in almost a decade. Here's a list of recent $ZEC exploits and bugs: March 1, 2018: BCTV14 zk-SNARK counterfeiting vulnerability (CVE-2019-7167) discovered (infinite counterfeit ZEC possible in Sprout pool). October 28, 2018: Sapling upgrade fixes the 2018 counterfeiting vulnerability. September 13, 2019: Security issue reported . November 8, 2019: CVE-2017-18350 response and "related fixes. " February 6, 2020: Sprout z-address wallet balance display bug. February 6, 2020: Consensus fork vulnerability. July 28, 2020: Sprout verification vulnerability introduced (bypass of proof checks). March 23, 2026: Sprout verification vulnerability disclosed (~25k ZEC counterfeiting risk; March 31, 2026). April 4, 2026: Multiple zcashd/Zebra issues reported (Orchard crashes, consensus gaps, turnstile bypass, integer issues). April 17, 2026: zcashd v6.12.1 and Zebra v4.3.1 fixes for the April bundle (including CVE-2026-34377 and others). May 2, 2026: Zebra v4.4.0 critical fixes (consensus, DoS, sigops undercount). May 29, 2026: Orchard shielded pool double-spending risk discovered. June 2–3, 2026: Emergency soft/hard fork for Orchard fix. This focuses on publicly notable/security-relevant issues; many minor bugs exist in routine updates but lack specific dated disclosures.

    Post summary

    The post catalogs multiple Zcash CVEs and their remedies, detailing technical aspects of each flaw while noting the corresponding patches without providing exploit proof or evidence of active attacks.

    2212761.8K
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34377 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cac… https://www.cve.org/CVERecord?id=CVE-2026-34377

    Post summary

    CVE-2026-34377 identifies a logic error in Zebra's transaction verification prior to zebrad 4.3.0 and zebra-consensus 5.0.1, with newer versions implying a patch has been released.

    0000096
    56.9K followersView on X
  • DailyCVE@dailycve
    General

    🔴 Zebra, Consensus Failure, #CVE-2026-34377 (High) https://dailycve.com/zebra-consensus-failure-cve-2026-34377-high/

    Post summary

    The post simply names a new CVE and provides a link, with no further details on exploitation, patches, or technical specifics.

    0000024
    175 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appzfndzebra-rust-
Appzfndzebra-consensus-rust-

Explore more