CVE-2026-41583: ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling

Published May 8, 2026
·
Updated

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes could thus accept and eventually mine a block that would be considered invalid by zcashd nodes, creating a consensus split between Zebra and zcashd nodes. In a similar vein, for V4 transactions, Zebra mistakenly used the "canonical" hash type when computing the sighash while zcashd (correctly per the spec) uses the raw value, which could also crate a consensus split. This issue has been patched in zebrad version 4.3.1 and zebra-script version 5.0.2.

Affected Software

4 affected components
Zebra zebrad<4.3.1
Zebra zebra-script<5.0.2
zfnd Zebra-script Rust<5.0.2
zfnd Zebrad Rust<4.3.1

Event History

May 8, 2026
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-41583?

CVE-2026-41583 has been classified with a medium severity level due to its potential impact on the consensus rules in ZEBRA.

2

How do I fix CVE-2026-41583?

To remediate CVE-2026-41583, upgrade to zebrad version 4.3.1 or higher and zebra-script version 5.0.2 or higher.

3

What applications are affected by CVE-2026-41583?

CVE-2026-41583 affects the ZEBRA software, specifically zebrad versions prior to 4.3.1 and zebra-script versions prior to 5.0.2.

4

What is the impact of exploiting CVE-2026-41583?

Exploiting CVE-2026-41583 could lead to consensus divergence, potentially compromising transaction validity within the Zcash network.

5

When was CVE-2026-41583 disclosed?

CVE-2026-41583 was disclosed as part of a security advisory related to ZEBRA, which was made public on its GitHub repository.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203