Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wc6w-gfmg-rf5p

Опубликовано: 02 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 7.4

Описание

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

8.3 High

CVSS4

7.4 High

CVSS3

Дефекты

CWE-347

8.3 High

CVSS4

7.4 High

CVSS3

Дефекты

CWE-347