OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104430

HIGH · CVSS 7.5 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Zebra zebrad 4.5.0 and zebra-script 7.0.0 are vulnerable due to a miscalculation of signature operations in P2SH redeem scripts, leading to a consensus divergence with zcashd. This flaw allows remote attackers to exploit low-threshold multisig redeem scripts, potentially causing Zebra nodes to reject valid blocks and stall off the blockchain. Organizations using these versions should prioritize patching to maintain network integrity and prevent disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104430
Severity
HIGH
CVSS
7.5
EPSS
0.41%

Original NVD Description

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.