PT-2026-33597 · Zebra · Zebra

·

CVE-2026-40880

·

Published

2026-04-18

·

Updated

2026-04-21

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zebra versions prior to 4.3.1
Description A logic error in the transaction verification cache allows a malicious miner to induce a consensus split. The issue stems from a performance optimization that skips transaction validation if the transaction was previously accepted into the mempool. This mechanism fails to account for height-dependent validity, such as expiry heights, lock times, or network upgrades. An attacker could submit a transaction valid for height H+1 but invalid for H+2, then mine it into a block at height H+2. Vulnerable nodes may accept the invalid block, leading to a chain fork and network partitioning from the rest of the Zcash network.
Recommendations Update to Zebra version 4.3.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40880
GHSA-XVJ8-PH7X-65GF

Affected Products

Zebra