CVE-2026-41583Disclosure(zfnd / zebra-script)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zfnd zebra-script systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes could thus accept and eventually mine a block that would be considered invalid by zcashd nodes, creating a consensus split between Zebra and zcashd nodes. In a similar vein, for V4 transactions, Zebra mistakenly used the "canonical" hash type when computing the sighash while zcashd (correctly per the spec) uses the raw value, which could also crate a consensus split. This issue has been patched in zebrad version 4.3.1 and zebra-script version 5.0.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-573

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zebra-script
  • zebrad

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-05-12); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
zebra-scriptzebrad

Deep dive

Activity timeline9 mentions / 3d
01345Mentions · 2026-05-08: 3Mentions · 2026-05-12: 5Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-08: 2Technical Details · 2026-05-12: 3Technical Details · 2026-05-14: 105-0805-1205-14
Signal classification3 categories
Disclosure
777.8%
Patch
111.1%
General
111.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-083
Disclosure2Patch1
2026-05-125
Disclosure4General1
2026-05-141
Disclosure1
Full discourse9 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Summary ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during…

    Post summary

    The snippet discusses CVE‑2026‑41583, noting that the applied fix created a separate issue involving invalid sighash error handling in ZEBRA.

    1000043
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-41583 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory cites CVE-2026-41583 as a critical vulnerability with a CVSS score of 9.1, but does not provide proof‑of‑concept, exploit details, or remediation guidance.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-41583 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces the CVE‑2026‑41583 vulnerability with its severity rating, but provides no additional detail on exploitation, mitigation, or technical specifics.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-41583-zfnd-zebra-script #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    Only a link and hashtags are provided; the snippet contains no direct evidence of PoC, exploitation, mitigation, or technical details.

    0001025
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-41583 (CVSS 9.1) — zfnd zebra-script. CVE: CVE-2026-41583 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    An advisory for CVE-2026-41583 specifying a critical CVSS score of 9.1 and indicating the severity status as critical.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-41583 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory ZEBRA is a Zcash node written entirely in Rust.

    Post summary

    The text announces a critical vulnerability (CVE‑2026‑41583) with a CVSS score of 9.1 and no further details on exploitation or mitigation.

    1000045
    210 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-41583 — CVSS 9.1/10 █████████░ ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/OddCpU9K41

    Post summary

    CVE-2026-41583 is a critical vulnerability in Zebra, with patches available for zebrad 4.3.1 and zebra-script 5.0.2.

    10000153
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44497 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separat… https://www.cve.org/CVERecord?id=CVE-2026-44497

    Post summary

    The tweet announces CVE‑2026‑44497, a vulnerability affecting older ZEBRA versions, pointing out that upgrading to zebrad 4.4.0 or zebra‑script 6.0.0 mitigates the issue.

    0001079
    57.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41583 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a… https://www.cve.org/CVERecord?id=CVE-2026-41583

    Post summary

    The statement announces a new CVE for the ZEBRA Zcash node, noting a validation failure before specific versions, but it does not offer technical details, exploitation evidence, or mitigation information.

    0000069
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appzfndzebra-script-rust-
Appzfndzebrad-rust-

Explore more