PT-2026-33597 · Zebra · Zebra

Sangsoo-Osec

·

Published

2026-04-18

·

Updated

2026-04-21

·

CVE-2026-40880

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zebra versions prior to 4.3.1
Description A logic error in the transaction verification cache allows a malicious miner to induce a consensus split. The issue stems from a performance optimization that skips transaction validation if the transaction was previously accepted into the mempool. This mechanism fails to account for height-dependent validity, such as expiry heights, lock times, or network upgrades. An attacker could submit a transaction valid for height H+1 but invalid for H+2, then mine it into a block at height H+2. Vulnerable nodes may accept the invalid block, leading to a chain fork and network partitioning from the rest of the Zcash network.
Recommendations Update to Zebra version 4.3.1.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-40880
GHSA-XVJ8-PH7X-65GF

Affected Products

Zebra