Security: ZcashFoundation/zebra
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Pre-handshake buffer capacity reservation based on attacker-claimed body lengthGHSA-h72h-ppcx-998p published
May 29, 2026 by mpguerraModerate -
Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parserGHSA-gf9r-m956-97qx published
May 29, 2026 by mpguerraCritical -
Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retentionGHSA-65jj-fmw8-468q published
May 29, 2026 by mpguerraModerate -
Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tipGHSA-2gf8-q9rr-jq3h published
May 29, 2026 by mpguerraModerate -
Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer PoisoningGHSA-h9hm-m2xj-4rq9 published
May 5, 2026 by mpguerraCritical -
Mempool transaction admission denial via single-peer inbound queue saturationGHSA-4fc2-h7jh-287c published
May 29, 2026 by mpguerraModerate -
Full node denial of service via crafted Sapling receiver in z_listunifiedreceiversGHSA-c8w6-x74f-vmg3 published
May 29, 2026 by mpguerraModerate -
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding outputGHSA-pvmv-cwg8-v6c8 published
May 4, 2026 by conradoplgCritical -
getblocks/getheaders locator CPU amplification via uncapped vector lengthGHSA-443g-gwgp-49x4 published
May 29, 2026 by mpguerraLow -
Full node denial of service via non-ASCII LongPollId in getblocktemplateGHSA-qv2r-v3mx-f4pf published
May 29, 2026 by mpguerraModerate