CVE-2026-104430: Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount
Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP1 through OP16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAXBLOCKSIGOPS count, causing Zebra nodes to reject it and stall off the chain.
Affected Software
Event History
Frequently Asked Questions
Which nodes are exposed to this consensus failure?
Zebra nodes running zebrad 4.5.0 or using zebra-script 7.0.0 are affected. The divergence occurs when such nodes evaluate blocks containing specially constructed P2SH spends that zcashd accepts.
What does an attacker need to exploit the issue?
An attacker needs only network access to broadcast P2SH spends using low-threshold multisig redeem scripts. No privileges or user interaction are required.
What is the operational impact if exploitation succeeds?
Affected Zebra nodes can reject a block that zcashd accepts because their inflated sigop count exceeds MAX_BLOCK_SIGOPS. The affected nodes then stall and stop following the chain.