zebra-state Security Analysis
zebra-state has 3 known security vulnerabilities in crates.io (Rust). Upgrade to version 7.0.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 7.0.0
Upgrading to 7.0.0 or later resolves all 3 known vulnerabilities in zebra-state. Update Cargo.toml: zebra-state = "7.0.0"
Is zebra-state in your project?
Check if you're affected and upgrade to 7.0.0 to stay secure.
Vulnerabilities
3 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-52736 Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache | HIGH | All versions | 7.0.0 |
| CVE-2026-52733 zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip | MEDIUM | All versions | 7.0.0 |
| CVE-2026-52739 Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection | MEDIUM | All versions | 7.0.0 |
About This Data
Vulnerability data for zebra-state is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related crates.io (Rust) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of zebra-state.