CVE-2026-41584: ZEBRA: rk Identity Point Panic in Transaction Verification
ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" value), however, the orchard crate which is used to verify Orchard proofs would panic when fed a rk with the identity value. Thus an attacker could send a crafted transaction that would make a Zebra node crash. This issue has been patched in zebrad version 4.3.1 and zebra-chain version 6.0.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41584?
CVE-2026-41584 has been classified as a high-severity vulnerability due to its potential impact on transaction verification.
How do I fix CVE-2026-41584?
To mitigate CVE-2026-41584, upgrade to zebrad version 4.3.1 or zebra-chain version 6.0.2 or later.
What software is affected by CVE-2026-41584?
CVE-2026-41584 affects zebrad versions prior to 4.3.1 and zebra-chain versions prior to 6.0.2.
What risks are associated with CVE-2026-41584?
Exploiting CVE-2026-41584 could lead to transaction verification failures, potentially compromising financial transactions on the Zcash network.
Is CVE-2026-41584 an issue in the Zcash protocol?
Yes, CVE-2026-41584 is a vulnerability within the Zcash protocol specifically related to transaction verification in the Orchard aspect.