Several high-severity flaws were disclosed in Zebra, the Rust-based Zcash node implementation, including bugs that can split consensus and remotely crash nodes. CVE-2026-34377 describes a transaction verification cache logic error that could let a malicious miner reuse a valid transaction ID with invalid authorization data, causing vulnerable Zebra nodes to accept an invalid block and diverge from the main Zcash chain. A related advisory said improper sighash hash-type handling could leave isolated Zebra nodes tracking a fraudulent ledger state, creating downstream risk for exchanges, merchants, infrastructure providers, and block explorers that rely on those nodes.
Additional Zebra issues can terminate nodes through denial-of-service conditions. CVE-2026-34202 allows a remote unauthenticated attacker to send a crafted V5 transaction that passes deserialization but panics during transaction ID calculation, while another flaw in Orchard signature verification can trigger a fatal panic when an identity point is used as a randomized validating key. A separate zebra-rpc bug can also crash the daemon through interrupted JSON-RPC requests, though exploitation is more limited because authentication is required and the interface binds to localhost by default. The affected issues were patched in zebrad 4.3.0, with related fixes in zebra-consensus 5.0.1 and zebra-chain 6.0.1.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
A report disclosed a denial-of-service flaw in Orchard signature verification used by Zebra, where an identity point on the Pallas curve can cause an unwrap on None and crash the node. In Zebra, the panic occurs on critical validation threads and leads to immediate node termination.
A report disclosed a denial-of-service vulnerability in zebra-rpc where interrupted JSON-RPC requests can trigger a Rust panic and abort the daemon. The issue requires authentication and is less likely to be exploited broadly because the RPC interface binds to localhost by default.
A later report described the Zebra consensus bug as potentially causing permanent divergence from the main Zcash chain and exposing exchanges, merchants, block explorers, and infrastructure providers to fraudulent ledger views. It also noted the practical severity was reduced because most Zcash mining power runs zcashd, so a Zebra-only fork would likely stall.
A new CVE, CVE-2026-34377, was published for a critical logic error in Zebra's transaction verification cache that could let a malicious miner trigger a consensus split. Affected Zebra nodes could accept an invalid block and diverge from invulnerable Zebra and Zcashd nodes.
Zebra patched the consensus failure issue in zebrad 4.3.0 and zebra-consensus 5.0.1, and patched the V5 transaction hash panic in zebrad 4.3.0 and zebra-chain 6.0.1. The references describe these fixes as addressing consensus-split and denial-of-service risks in affected versions.
The vulnerability later tracked as CVE-2026-34202 was received by security-advisories@github.com on March 31, 2026. The flaw could let a remote unauthenticated attacker crash a Zebra node via a specially crafted V5 transaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.