← Vulnerability feed

Vulnerability record · CVE-2026-40880 · published 21 April 2026

CVE-2026-40880: Zfnd zebra-consensus vulnerability

Zfnd · Zebra Consensus

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This vulnerability is fixed in zebrad version 4.3.1 and zebra-consensus version 5.0.2.

7.2 CVSS 4.0 High EPSS 0.44% · top 64.0% CWE-1025 · CWE-1025
7.2CVSS 4.0 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This vulnerability is fixed in zebrad version 4.3.1 and zebra-consensus version 5.0.2.

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40880 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-44497Zfnd zebra-script improper verification of cryptographic signature vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 int…EPSS 0.30%9.3CVE-2026-41583Zfnd zebra-script vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra fai…EPSS 0.47%9.2CVE-2026-44498Zfnd zebrad vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against …EPSS 0.38%9.2CVE-2026-41584Zfnd zebra-chain vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a …EPSS 0.46%8.4CVE-2026-34377Zfnd zebra improper verification of cryptographic signature vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic error in Zebra's transaction…EPSS 0.38%6.9CVE-2026-41585Zfnd zebra-rpc vulnerabilityZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2,…EPSS 0.43%6.3CVE-2026-40881Zfnd zebra-network allocation without limits vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 mess…EPSS 0.46%5.3CVE-2026-44500Zfnd zebra-chain allocation without limits vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2026-40880), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.