zebrad Security Analysis
zebrad has 19 known security vulnerabilities in crates.io (Rust). Upgrade to version 5.0.0 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 5.0.0
Upgrading to 5.0.0 or later resolves all 19 known vulnerabilities in zebrad. Update Cargo.toml: zebrad = "5.0.0"
Is zebrad in your project?
Check if you're affected and upgrade to 5.0.0 to stay secure.
Vulnerabilities
19 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-52735 zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser | CRITICAL | All versions | 4.5.0 |
| CVE-2026-54496 Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness | CRITICAL | All versions | 5.0.0 |
| CVE-2026-44497 Zebra has Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale Buffer | CRITICAL | All versions | 4.4.0 |
| CVE-2026-41583 Zebra Vulnerable to Consensus Divergence in Transparent Sighash Hash-Type Handling | CRITICAL | All versions | 4.3.1 |
| CVE-2026-34202 Zebra node crash — V5 transaction hash panic (P2P reachable) | CRITICAL | All versions | 4.3.0 |
| GHSA-pvmv-cwg8-v6c8 Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output | CRITICAL | All versions | 4.4.1 |
| CVE-2026-41584 Zebra has rk Identity Point Panic in Transaction Verification | CRITICAL | All versions | 4.3.1 |
| CVE-2026-44498 Zebra's Block Validator Undercounts Coinbase and P2SH Sigops | CRITICAL | All versions | 4.4.0 |
| GHSA-cwfq-rfcr-8hmp Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs | CRITICAL | All versions | 4.4.0 |
| CVE-2026-40880 Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks | HIGH | All versions | 4.3.1 |
| CVE-2026-34377 Zebra has a Consensus Failure due to Improper Verification of V5 Transactions | HIGH | All versions | 4.3.0 |
| CVE-2026-52829 Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update | HIGH | All versions | 4.5.0 |
| CVE-2026-52736 Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache | HIGH | All versions | 4.5.0 |
| CVE-2026-44499 Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning | HIGH | All versions | 4.4.0 |
| CVE-2026-52733 zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip | MEDIUM | All versions | 4.5.0 |
| CVE-2026-52731 zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate | MEDIUM | All versions | 4.5.0 |
| CVE-2026-41585 Zebra Vulnerable to Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients | MEDIUM | All versions | 4.3.1 |
| CVE-2026-52739 Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection | MEDIUM | All versions | 4.5.0 |
| CVE-2026-44500 Zebra Vulnerable to Allocation Amplification in Inbound Network Deserializers | MEDIUM | All versions | 4.4.0 |
About This Data
Vulnerability data for zebrad is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related crates.io (Rust) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of zebrad.