The Zfnd develops Zebra, a privacy-focused blockchain implementation with a modular architecture spanning consensus, networking, and chain components; its vulnerability footprint, while concentrated, reaches critical-severity outcomes reflecting the cryptographic and resource-management demands of decentralized systems. The recurring weakness classes—resource-exhaustion without throttling, cryptographic-signature verification flaws, reachable assertions, comparison logic errors, and untrusted deserialization—center on the protocol parsing, consensus validation, and peer-communication layers that define a blockchain node's attack surface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zfnd over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44497CRITICAL ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to | May 8, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-41583CRITICAL ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rul | May 8, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-44498HIGH ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MA | May 8, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-41584HIGH ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized | May 8, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-34377HIGH ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction verification cache could allow | Mar 31, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-34202HIGH ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote | Mar 31, 2026 | 7.5 | 27 | NO | NO |
CVE-2026-40881HIGH ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of | Apr 21, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-40880HIGH ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow | Apr 21, 2026 | 8.1 | 26 | NO | NO |
CVE-2026-41585MEDIUM ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSO | May 8, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-44500MEDIUM ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deseria | May 8, 2026 | 5.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zfnd.
Media articles that mention a CVE ID that affects a product developed by Zfnd — matched by CVE ID, not by vendor name.