OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104437

HIGH · CVSS 7.4 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Zebra versions prior to 4.4.0 are vulnerable to a consensus divergence issue in V5 transparent signature verification, which allows attackers to create malformed transactions that the system accepts but are rejected by zcashd. This could lead to discrepancies in transaction validation and potential blockchain forks. Organizations using Zebra for Zcash transactions should prioritize addressing this vulnerability to maintain network integrity and prevent exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104437
Severity
HIGH
CVSS
7.4
EPSS
0.21%

Original NVD Description

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.