CVE-2026-104430: Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount

Published Oct 2, 2026
·
Updated

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP1 through OP16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAXBLOCKSIGOPS count, causing Zebra nodes to reject it and stall off the chain.

Affected Software

2 affected components
Zebra zebrad=4.5.0
Zebra zebra-script=7.0.0

Event History

Oct 2, 2026
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which nodes are exposed to this consensus failure?

Zebra nodes running zebrad 4.5.0 or using zebra-script 7.0.0 are affected. The divergence occurs when such nodes evaluate blocks containing specially constructed P2SH spends that zcashd accepts.

2

What does an attacker need to exploit the issue?

An attacker needs only network access to broadcast P2SH spends using low-threshold multisig redeem scripts. No privileges or user interaction are required.

3

What is the operational impact if exploitation succeeds?

Affected Zebra nodes can reject a block that zcashd accepts because their inflated sigop count exceeds MAX_BLOCK_SIGOPS. The affected nodes then stall and stop following the chain.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203