CVE-2026-34202

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
31/03/2026
Last modified:
07/04/2026

Description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation. This issue has been patched in zebrad version 4.3.0 and zebra-chain version 6.0.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zfnd:zebra:*:*:*:*:*:rust:*:* 4.3.0 (excluding)
cpe:2.3:a:zfnd:zebra-chain:*:*:*:*:*:rust:*:* 6.0.1 (excluding)