CVE-2026-40881Disclosure(zfnd / zebra-network)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zfnd zebra-network systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (over 233,000) that was derived from the 2 MiB message size limit. This is much larger than the actual limit of 1,000 messages from the specification. Zebra would eventually check that limit but, at that point, the memory for the larger vector was already allocated. An attacker could cause out-of-memory aborts in Zebra by sending multiple such messages over different connections. This vulnerability is fixed in zebrad version 4.3.0 and zebra-network version 5.0.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zebra-network
  • zebrad

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-18); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
zebra-networkzebrad

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-18: 3Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-18: 3Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 104-1804-1904-21
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-183
Disclosure3
2026-04-191
Patch1
2026-04-211
General1
Full discourse5 posts
  • Zcash Türkiye@ZcashTR
    Patch

    🚨 Zebra 4.3.1 yayımlandı – Kritik güncelleme! Zcash Vakfı, Zebra node yazılımı için önemli güvenlik düzeltmeleri içeren 4.3.1 sürümünü duyurdu. Tüm node operatörlerinin acilen güncelleme yapması gerekiyor. 🔍 Kritik güvenlik düzeltmeleri: • Konsensüs hatası (CVE-2026-40880): İşlem doğrulama önbelleğindeki mantık hatası, kötü niyetli bir madencinin ağda zincir bölünmesine yol açmasına imkan tanıyordu → tamamen kaldırıldı • Bellek tüketimi açığı (CVE-2026-40881): addr/addrv2 mesajları üzerinden node’un çökertilmesi mümkün → bellek tahsisi sınırlandı • Sighash doğrulama hataları: Zebra ile zcashd arasında işlem kabul farkı oluşturan kritik tutarsızlıklar giderildi • Orchard işlemlerinde panic hatası: Özel hazırlanmış işlem ile node çökertme riski ortadan kaldırıldı • JSON-RPC DoS: Yarım bırakılan isteklerle node çökertilmesi engellendi 🛡️ Güvenlik iyileştirmeleri: • CI süreçlerine tedarik zinciri ve lisans denetimleri eklendi • SECURITY.md güncellendi (güvenli bildirim kanalı) • Geçmiş güvenlik kayıtları daha şeffaf hale getirildi ⚙️ Yeni özellikler: • 🐳 Docker tabanlı madencilik kurulumu • 🔄 Otomatik checkpoint ve destek sonu blok yüksekliği güncellemeleri ⚠️ Önemli: Bu sürümdeki açıklar doğrudan konsensüs bölünmesine ve node çökmesine neden olabiliyor. ➡️ Herhangi bir workaround yok — güncelleme tek çözüm. 🔗 Kaynak: https://forum.zcashcommunity.com/t/zebra-4-3-1-critical-security-fixes-dockerized-mining-and-ci-hardening/55389 #Zcash #Crypto #Blockchain #NodeOperators #privacy

    Post summary

    The tweet announces the zebra 4.3.1 release, detailing critical security fixes for several CVEs and urging node operators to update, with no workaround available.

    1302402.2K
    341 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40881 Denial of Service via Memory Exhaustion in ZEBRA Prior to Version... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40881 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post merely advertises a DoS vulnerability (CVE-2026-40881) in ZEBRA and links to a vulnerability database entry, without providing any proof of concept, exploitation details, or mitigation steps.

    0000034
    4.0K followersView on X
  • Zk_nd3r@Zk_nd3r
    Disclosure

    CVE-2026-40881 published. zebra addr/addrv2 deserialization DoS reporter credit on GHSA-xr93-pcq3-pxf8. coordinated via @zcashfoundation, thanks mpguerra, oxarbitrage, conradoplg.

    Post summary

    CVE-2026-40881 is a disclosed deserialization DoS vulnerability in zebra addr/addrv2, credited on GHSA and coordinated by the Zcash Foundation.

    00000229
    22 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Zebra, Denial of Service, #CVE-2026-40881 (Moderate) https://dailycve.com/zebra-denial-of-service-cve-2026-40881-moderate/

    Post summary

    A new Zebra Denial of Service vulnerability (CVE-2026-40881) has been disclosed as Moderate severity, but no PoC, exploit code, active exploitation, or patch information is provided.

    0000074
    181 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Zebra (JSON-RPC), Denial of Service (DoS), #CVE-2026-40881 (Moderate) https://dailycve.com/zebra-json-rpc-denial-of-service-dos-cve-2026-40881-moderate/

    Post summary

    The post announces CVE‑2026‑40881, a moderate severity denial‑of‑service flaw in Zebra JSON‑RPC, without providing exploitation or mitigation details.

    0000085
    181 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appzfndzebra-network-rust-
Appzfndzebrad-rust-

Explore more