CVE-2026-104437: Zebra before 4.4.0 Consensus Split via SIGHASH_SINGLE Missing-Output Handling
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASHSINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this consensus-split issue?
Zcash Foundation Zebra deployments running a version before 4.4.0 are affected. The issue concerns V5 transparent signature verification.
What must an attacker do to trigger the problem?
An attacker must craft a V5 transaction using SIGHASH_SINGLE with fewer outputs than inputs, so that an input has no corresponding output. Zebra computes a ZIP-244 digest for this case rather than failing verification.
What is the operational impact for node operators or miners?
Zebra can accept the malformed transaction and include it in block templates returned by getblocktemplate. A block produced from such a template can be rejected by zcashd, creating a consensus divergence.
How can an operator determine whether they are affected?
Check the deployed Zebra version. Versions before 4.4.0 are affected; version 4.4.0 is not identified as affected in the provided data.