Loading...
Skip to main content
crates.io (Rust)

zebrad Security Analysis

zebrad has 19 known security vulnerabilities in crates.io (Rust). Upgrade to version 5.0.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

19 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 5.0.0

Upgrading to 5.0.0 or later resolves all 19 known vulnerabilities in zebrad. Update Cargo.toml: zebrad = "5.0.0"

Is zebrad in your project?

Check if you're affected and upgrade to 5.0.0 to stay secure.

19
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

19 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-52735
zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser
CRITICAL
All versions4.5.0
CVE-2026-54496
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
CRITICAL
All versions5.0.0
CVE-2026-44497
Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer
CRITICAL
All versions4.4.0
CVE-2026-41583
Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling
CRITICAL
All versions4.3.1
CVE-2026-34202
Zebra node crash — V5 transaction hash panic (P2P reachable)
CRITICAL
All versions4.3.0
GHSA-pvmv-cwg8-v6c8
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output
CRITICAL
All versions4.4.1
CVE-2026-41584
Zebra has rk Identity Point Panic in Transaction Verification
CRITICAL
All versions4.3.1
CVE-2026-44498
Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
CRITICAL
All versions4.4.0
GHSA-cwfq-rfcr-8hmp
Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs
CRITICAL
All versions4.4.0
CVE-2026-40880
Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks
HIGH
All versions4.3.1
CVE-2026-34377
Zebra has a Consensus Failure due to Improper Verification of V5 Transactions
HIGH
All versions4.3.0
CVE-2026-52829
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update
HIGH
All versions4.5.0
CVE-2026-52736
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache
HIGH
All versions4.5.0
CVE-2026-44499
Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
HIGH
All versions4.4.0
CVE-2026-52733
zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip
MEDIUM
All versions4.5.0
CVE-2026-52731
zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate
MEDIUM
All versions4.5.0
CVE-2026-41585
Zebra Vulnerable to Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients
MEDIUM
All versions4.3.1
CVE-2026-52739
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection
MEDIUM
All versions4.5.0
CVE-2026-44500
Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers
MEDIUM
All versions4.4.0

About This Data

Vulnerability data for zebrad is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related crates.io (Rust) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of zebrad.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed