Security: ZcashFoundation/zebra
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Full node denial of service via crafted Sapling receiver in z_listunifiedreceiversGHSA-c8w6-x74f-vmg3 published
May 29, 2026 by mpguerraModerate -
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding outputGHSA-pvmv-cwg8-v6c8 published
May 4, 2026 by conradoplgCritical -
getblocks/getheaders locator CPU amplification via uncapped vector lengthGHSA-443g-gwgp-49x4 published
May 29, 2026 by mpguerraLow -
Full node denial of service via non-ASCII LongPollId in getblocktemplateGHSA-qv2r-v3mx-f4pf published
May 29, 2026 by mpguerraModerate -
Consensus Divergence in Transparent Sighash Hash-Type Handling due to Stale BufferGHSA-gq4h-3grw-2rhv published
May 2, 2026 by mpguerraCritical -
Allocation Amplification in Inbound Network DeserializersGHSA-438q-jx8f-cccv published
May 2, 2026 by mpguerraModerate -
Zebra Transparent SIGHASH_SINGLE Corresponding-Output Handling Diverges From zcashdGHSA-cwfq-rfcr-8hmp published
May 2, 2026 by mpguerraCritical -
Block Validator Undercounts Coinbase and P2SH SigopsGHSA-jv4h-j224-23cc published
May 2, 2026 by mpguerraCritical -
Denial of Service via Interrupted JSON-RPC Requests from Authenticated ClientsGHSA-29x4-r6jv-ff4w published
Apr 17, 2026 by mpguerraModerate -
rk Identity Point Panic in Transaction VerificationGHSA-452v-w3gx-72wg published
Apr 17, 2026 by mpguerraCritical