Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xvj8-ph7x-65gf | Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks |
Mon, 27 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zfnd
Zfnd zebra-consensus Zfnd zebrad |
|
| CPEs | cpe:2.3:a:zfnd:zebra-consensus:*:*:*:*:*:rust:*:* cpe:2.3:a:zfnd:zebrad:*:*:*:*:*:rust:*:* |
|
| Vendors & Products |
Zfnd
Zfnd zebra-consensus Zfnd zebrad |
|
| Metrics |
cvssV3_1
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zcashfoundation
Zcashfoundation zebra-consensus Zcashfoundation zebrad |
|
| Vendors & Products |
Zcashfoundation
Zcashfoundation zebra-consensus Zcashfoundation zebrad |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This vulnerability is fixed in zebrad version 4.3.1 and zebra-consensus version 5.0.2. | |
| Title | Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks | |
| Weaknesses | CWE-1025 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T19:52:58.880Z
Reserved: 2026-04-15T15:57:41.719Z
Link: CVE-2026-40880
Updated: 2026-04-21T19:52:54.543Z
Status : Analyzed
Published: 2026-04-21T20:17:01.687
Modified: 2026-04-27T18:26:19.257
Link: CVE-2026-40880
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:45:46Z
Github GHSA