CVE Database
/

CVE-2026-34202

Back to search

CVE-2026-34202

Published: Mar 31, 2026

Modified: Mar 31, 2026

PUBLISHED

Description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation. This issue has been patched in zebrad version 4.3.0 and zebra-chain version 6.0.1.

VendorProductVersions

ZcashFoundation

zebra

affected
< 4.3.0

ZcashFoundation

zebra-chain

affected
< 6.0.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now