Loading...
Skip to main content

CVE-2026-41584

CRITICAL

Zebra has rk Identity Point Panic in Transaction Verification

Published April 18, 2026Updated May 12, 2026Source: osv

Summary

# rk Identity Point Panic in Transaction Verification ## Summary Orchard transactions contain a `rk` field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" value), however, the `orchard` crate which is used to verify Orchard proofs would panic when fed a `rk` with the identity value. Thus an attacker could send a crafted transaction that would make a Zebra node crash. ## Severity **Critical** - This is a Denial of Service Vulnerability that could allow an attacker to crash Zebra nodes. ## Affected Versions All Zebra versions prior to **version 4.3.1**. ## Description The vulnerability exists in the `circuits.rs` file of the `orchard` crate; it attempts to get the coordinates of the `rk` value and calls `unwrap()` on the results, which causes a panic if `rk` is the identity. Zebra parses `rk` as a byte vector; it creates an Orchard "bundle" using the `orchard` crate and then calls the same crate to verify it, triggering the panic. An attacker could exploit this by: 1. Creating a transaction with a identity `rk` 2. Submitting it to a Zebra node, making it crash ## Impact **Denial of Service** * **Attack Vector:** Network. * **Effect:** Node crash. * **Scope:** Any impacted Zebra node. ## Fixed Versions This issue is fixed in **Zebra 4.3.1**. The fix was agreed with `zcashd` developers (which has the same issue) to not allow the identity `rk` anymore and change the specification as such. Zebra now does this when parsing a transaction. This was deemed easier than fixing the issue in `orchard`, which would make the bug public before the nodes could be patched. ## Mitigation Users should upgrade to **Zebra 4.3.1** or later immediately. There are no known workarounds for this issue. Immediate upgrade is the only way to ensure the node remains not vulnerable to denial of service. ## Credits Thanks to Alex “Scalar” Sol for finding and reporting the issue.

Remediation

Upgrade to the fixed version using your package manager.

Cargo
Update zebra-chain to 6.0.2 or later
cargo update -p zebra-chain --precise 6.0.2
Cargo
Update zebrad to 4.3.1 or later
cargo update -p zebrad --precise 4.3.1

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (2)

PackageEcosystemAffectedFixed In
zebra-chain
crates.io
All versions6.0.2
zebrad
crates.io
All versions4.3.1

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 7.5 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Frequently Asked Questions

What is CVE-2026-41584?
Zebra has rk Identity Point Panic in Transaction Verification This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 7.5/10).
How do I check if my project is affected by CVE-2026-41584?
CVE-2026-41584 affects zebra-chain and zebrad. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-41584 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
7.5

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-452v-w3gx-72wg

Related CVEs

  • CVE-2026-41583
    CRITICAL

    Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling

  • CVE-2026-34202
    CRITICAL

    Zebra node crash — V5 transaction hash panic (P2P reachable)

  • CVE-2026-34377
    HIGH

    Zebra has a Consensus Failure due to Improper Verification of V5 Transactions

  • CVE-2026-52736
    HIGH

    Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache

  • CVE-2026-52829
    HIGH

    Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update

  • CVE-2026-41585
    MEDIUM

    Zebra Vulnerable to Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients

  • CVE-2026-52733
    MEDIUM

    zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip

  • CVE-2026-44500
    MEDIUM

    Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies