Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zcashfoundation
Zcashfoundation zebra |
|
| Vendors & Products |
Zcashfoundation
Zcashfoundation zebra |
Fri, 02 Oct 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects. | |
| Title | Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling | |
| First Time appeared |
Zfnd
Zfnd zebra |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:zfnd:zebra:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zfnd
Zfnd zebra |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T11:38:13.855Z
Reserved: 2026-10-02T00:50:26.604Z
Link: CVE-2026-104437
No data.
Status : Received
Published: 2026-10-02T12:17:14.357
Modified: 2026-10-02T12:17:14.357
Link: CVE-2026-104437
No data.
OpenCVE Enrichment
Updated: 2026-10-02T13:00:13Z
-
CWE-347
Improper Verification of Cryptographic Signature