Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-104437

Опубликовано: 02 окт. 2026
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

EPSS

Процентиль: 9%
0.00205
Низкий

7.4 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.4
github
2 дня назад

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.

EPSS

Процентиль: 9%
0.00205
Низкий

7.4 High

CVSS3

Дефекты

CWE-347