CVE-2026-44497Disclosure(zfnd / zebra-script)

LOWCVSS 9.1 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch zfnd zebra-script systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computation. Instead of returning an error, the normal flow would resume, and the input sighash buffer would be left untouched. In scenarios where a previous signature validation could leave a valid sighash in the buffer, an invalid hash-type could be incorrectly accepted, which would create a consensus split between Zebra and zcashd nodes. This issue has been patched in zebrad version 4.4.0 and zebra-script version 6.0.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zebra-script
  • zebrad

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • General: 4 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-06-10)
  • 10 total mentions across 3 days

Affected systems

Vendors
Products
zebra-scriptzebrad

Deep dive

Activity timeline10 mentions / 3d
01234Mentions · 2026-05-08: 3Mentions · 2026-05-14: 3Mentions · 2026-06-10: 4Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-14: 2Technical Details · 2026-06-10: 105-0805-1406-10
Signal classification3 categories
Disclosure
550.0%
General
440.0%
Patch
110.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-083
Disclosure1General1Patch1
2026-05-143
Disclosure1General2
2026-06-104
Disclosure3General1
Full discourse10 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources (Zcash Advisory) The Stale Buffer Trap: CVE-2026-44497 Breaks Zebra Consensus—Network Partition & Double-Spend Risk Imminent

    Post summary

    A new CVE (CVE‑2026‑44497) has been announced, indicating that the Zcash Zebra consensus could be broken, leading to potential network partitions and double‑spend risks, but no further technical, exploit or mitigation details are provided.

    1000062
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    The Stale Buffer Trap: CVE-2026-44497 Shatters Zebra Consensus—Network Partition & Double-Spend Risk. When Zebra processes transparent transactions, it calls into C++ code to verify transaction signatures using the SIGHASH digest.

    Post summary

    Short text referencing CVE‑2026‑44497 in Zebra’s transparent transaction processing, but lacks concrete evidence of exploitation, detailed technical description, or patch information.

    1000033
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened On May 8, 2026, the Zcash Foundation disclosed CVE-2026-44497, a consensus-critical vulnerability in the Zebra full-node implementation affecting version 4.3.1. The flaw stems from improper buffer management in the Rust-to-C++ FFI layer that wraps Bitcoin…

    Post summary

    Zcash Foundation disclosed CVE‑2026‑44497, a consensus‑critical buffer‑management flaw in the Zebra full‑node implementation, providing technical details but no evidence of a PoC, exploit, or patch.

    1000068
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Stale Buffer Trap: CVE-2026-44497 Breaks Zebra Consensus—Network Partition & Double-Spend Risk Imminent When Zebra processes transparent transactions, it calls into C++ code to verify transaction signatures using the SIGHASH digest.

    Post summary

    The text announces CVE-2026-44497 as a potential risk to Zebra’s consensus, but provides no proof of concept, exploit details, or mitigation information.

    1000033
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-44497 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory ZEBRA is a Zcash node written entirely in Rust.

    Post summary

    The entry announces a critical advisory for CVE-2026-44497 affecting the ZEBRA Zcash node, providing its CVSS rating and severity, but offers no further exploitation or remediation details.

    1000047
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.1 CRITICAL · CVE-2026-44497 · 9.1 → 4.4.0 CVE: CVE-2026-44497 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text lists only the CVSS score, severity, and CVE identifier, confirming a critical vulnerability but providing no indication of proof of concept, exploit code, active exploitation, patches, or debunking.

    1000034
    210 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44497 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separat… https://www.cve.org/CVERecord?id=CVE-2026-44497

    Post summary

    The text merely references CVE‑2026‑44497 without providing any substantive details, exploit links, or mitigation information.

    0001079
    57.5K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-44497-zfnd-zebra-script #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post simply links to a research page for CVE-2026-44497, providing no further details on proof of concept, exploit availability, active exploitation, patches, or technical specifics.

    0000021
    210 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 CVE-2026-44497 in Zebra may cause consensus failures, risking network integrity and opening the door to malicious activity. Upgrade to the patched version now. 🔎 https://vulert.com/vuln-db/CVE-2026-44497 #CVE #BlockchainSecurity #CyberSecurity #Vulert https://t.co/TRUDLdWTBd

    Post summary

    The tweet highlights the CVE-2026-44497 vulnerability in Zebra, noting consensus failures and advising users to upgrade to a patched version.

    0000033
    125 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Zebra, Consensus Divergence, #CVE-2026-44497 (Critical) https://dailycve.com/zebra-consensus-divergence-cve-2026-44497-critical/

    Post summary

    The post announces a critical CVE (CVE‑2026‑44497) called Zebra, Consensus Divergence, but provides no additional technical detail, PoC, or evidence of exploitation.

    0000035
    196 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appzfndzebra-script-rust-
Appzfndzebrad-rust-

Explore more