CVE-2026-40880Disclosure(zfnd / zebra-consensus)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zfnd zebra-consensus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This vulnerability is fixed in zebrad version 4.3.1 and zebra-consensus version 5.0.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1025

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zebra-consensus
  • zebrad

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-18); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
zebra-consensuszebrad

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 104-1804-1904-21
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-181
Disclosure1
2026-04-191
Patch1
2026-04-211
General1
Full discourse3 posts
  • Zcash Türkiye@ZcashTR
    Patch

    🚨 Zebra 4.3.1 yayımlandı – Kritik güncelleme! Zcash Vakfı, Zebra node yazılımı için önemli güvenlik düzeltmeleri içeren 4.3.1 sürümünü duyurdu. Tüm node operatörlerinin acilen güncelleme yapması gerekiyor. 🔍 Kritik güvenlik düzeltmeleri: • Konsensüs hatası (CVE-2026-40880): İşlem doğrulama önbelleğindeki mantık hatası, kötü niyetli bir madencinin ağda zincir bölünmesine yol açmasına imkan tanıyordu → tamamen kaldırıldı • Bellek tüketimi açığı (CVE-2026-40881): addr/addrv2 mesajları üzerinden node’un çökertilmesi mümkün → bellek tahsisi sınırlandı • Sighash doğrulama hataları: Zebra ile zcashd arasında işlem kabul farkı oluşturan kritik tutarsızlıklar giderildi • Orchard işlemlerinde panic hatası: Özel hazırlanmış işlem ile node çökertme riski ortadan kaldırıldı • JSON-RPC DoS: Yarım bırakılan isteklerle node çökertilmesi engellendi 🛡️ Güvenlik iyileştirmeleri: • CI süreçlerine tedarik zinciri ve lisans denetimleri eklendi • SECURITY.md güncellendi (güvenli bildirim kanalı) • Geçmiş güvenlik kayıtları daha şeffaf hale getirildi ⚙️ Yeni özellikler: • 🐳 Docker tabanlı madencilik kurulumu • 🔄 Otomatik checkpoint ve destek sonu blok yüksekliği güncellemeleri ⚠️ Önemli: Bu sürümdeki açıklar doğrudan konsensüs bölünmesine ve node çökmesine neden olabiliyor. ➡️ Herhangi bir workaround yok — güncelleme tek çözüm. 🔗 Kaynak: https://forum.zcashcommunity.com/t/zebra-4-3-1-critical-security-fixes-dockerized-mining-and-ci-hardening/55389 #Zcash #Crypto #Blockchain #NodeOperators #privacy

    Post summary

    The forum post announces the release of Zebra 4.3.1, emphasises that it contains critical fixes for CVE‑2026‑40880 and CVE‑2026‑40881, and stresses that no workarounds exist—an immediate update is mandatory.

    1302402.2K
    341 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40880 Consensus Split via Transaction Verification Cache Logic Error in Zebra https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40880

    Post summary

    The post lists CVE‑2026‑40880, describing a logic error in Zebra that could cause a consensus split, but provides no PoC, exploit details, patch information, or evidence of active exploitation.

    0000039
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Zebra, Consensus Bypass, #CVE-2026-40880 (High) https://dailycve.com/zebra-consensus-bypass-cve-2026-40880-high/

    Post summary

    The post announces the identification of CVE‑2026‑40880, a high‑severity Consensus Bypass vulnerability in Zebra, without offering detailed technical data, exploitation proof, or mitigation guidance.

    0000042
    181 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appzfndzebra-consensus-rust-
Appzfndzebrad-rust-

Explore more