CVE-2026-34377 describes a high-severity logic error in Zebra's transaction verification cache, affecting zebrad versions prior to 4.3.0 and zebra-consensus prior to 5.0.1. This vulnerability allows a malicious miner to induce a consensus split within the Zcash network by causing vulnerable Zebra nodes to accept invalid blocks. Rated 8.4 CVSS (High), the flaw is network-exploitable with high privileges, posing a significant risk to network integrity and availability for affected nodes. While there is no evidence of active exploitation or public exploit code, the vulnerability has received limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.0CPE matchmatch criteria | cpe:2.3:a:zfnd:zebra:*:*:*:*:*:rust:*:* | ||
< 5.0.1CPE matchmatch criteria | cpe:2.3:a:zfnd:zebra-consensus:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.