CVE-2026-104430
HIGH
8,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
7,5
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.
628
Function Call with Incorrectly Specified Arguments
DraftCommon Consequences
Security Scopes Affected:
Other
Access Control
Potential Impacts:
Quality Degradation
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-2prc-cj5x-4443
https://www.vulncheck.com/advisories/zebra-4.5.0-consensus-split-via-p2sh-sigop…