OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104435

HIGH · CVSS 7.4 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Zebra zebrad 4.4.0 and zebra-script 6.0.0 are vulnerable due to their failure to enforce the ZIP-244 consensus rule, allowing the acceptance of V5 transactions that are improperly signed. This weakness enables attackers to create and broadcast transactions that could lead to a network consensus split, undermining the integrity of the blockchain. Organizations using these versions should prioritize remediation to prevent potential exploitation and ensure network stability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104435
Severity
HIGH
CVSS
7.4
EPSS
0.21%

Original NVD Description

Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.