CVE-2026-104435: Zebra 4.4.0 Consensus Divergence via V5 SIGHASH_SINGLE Without Output
Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASHSINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network consensus split.
Affected Software
Event History
Frequently Asked Questions
Which Zebra components are affected?
The affected components are zebrad 4.4.0 and zebra-script 6.0.0.
What must an attacker send to trigger the inconsistency?
An attacker must broadcast a crafted V5 transaction with more transparent inputs than outputs, where an input uses SIGHASH_SINGLE without a corresponding output. The transaction is accepted by Zebra but rejected by zcashd.
How can an operator determine whether they are exposed?
Operators using zebrad 4.4.0 or zebra-script 6.0.0 are affected by the described consensus-rule enforcement failure. The issue concerns validation of V5 transparent-input transactions.