Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8m29-fpq5-89jj | Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling |
Sat, 09 May 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zcashfoundation
Zcashfoundation zebra |
|
| Vendors & Products |
Zcashfoundation
Zcashfoundation zebra |
Fri, 08 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zfnd
Zfnd zebra-script Zfnd zebrad |
|
| CPEs | cpe:2.3:a:zfnd:zebra-script:*:*:*:*:*:rust:*:* cpe:2.3:a:zfnd:zebrad:*:*:*:*:*:rust:*:* |
|
| Vendors & Products |
Zfnd
Zfnd zebra-script Zfnd zebrad |
|
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes could thus accept and eventually mine a block that would be considered invalid by zcashd nodes, creating a consensus split between Zebra and zcashd nodes. In a similar vein, for V4 transactions, Zebra mistakenly used the "canonical" hash type when computing the sighash while zcashd (correctly per the spec) uses the raw value, which could also crate a consensus split. This issue has been patched in zebrad version 4.3.1 and zebra-script version 5.0.2. | |
| Title | ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling | |
| Weaknesses | CWE-573 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T19:42:57.297Z
Reserved: 2026-04-21T14:15:21.959Z
Link: CVE-2026-41583
Updated: 2026-05-08T19:42:47.215Z
Status : Analyzed
Published: 2026-05-08T15:16:41.070
Modified: 2026-05-08T18:44:58.830
Link: CVE-2026-41583
No data.
OpenCVE Enrichment
Updated: 2026-05-09T00:30:20Z
Github GHSA