Vulnerabilities in ZcashFoundation

23 results
Vexday analysis

A Zcash Foundation apresenta 13 vulnerabilidades catalogadas, com 8 publicadas nos últimos 90 dias, indicando atividade recente de descoberta. Nenhuma vulnerabilidade está sob exploração ativa conforme CISA KEV, mas 6 são críticas (CVSS alto), predominantemente relacionadas a CWE-770 (alocação de recursos sem limite). O risco atual é moderado, concentrado em gestão deficiente de recursos que pode levar a negação de serviço ou consumo excessivo.

CVE-2026-34202CRITICALZebra node crash — V5 transaction hash panic (P2P reachable)EPSS 0.9%CVE-2026-52736HIGHZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cacheEPSS 0.6%CVE-2026-52829HIGHZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address BookEPSS 0.6%CVE-2026-44499HIGHZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer PoisoningEPSS 0.5%CVE-2026-52731MEDIUMZEBRA: Full node denial of service via non-ASCII LongPollId in getblocktemplateEPSS 0.5%CVE-2026-52739MEDIUMZEBRA: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier RejectionEPSS 0.5%CVE-2026-52734MEDIUMZEBRA: Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retentionEPSS 0.5%CVE-2026-52735CRITICALZEBRA: Consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parserEPSS 0.5%CVE-2026-52732MEDIUMZEBRA: Mempool transaction admission denial via single-peer inbound queue saturationEPSS 0.5%CVE-2026-52738MEDIUMZEBRA: Finalized address balance credit-first overflow on consensus-valid blocksEPSS 0.5%CVE-2026-41583CRITICALZEBRA: Consensus Divergence in Transparent Sighash Hash-Type HandlingEPSS 0.5%CVE-2026-41584CRITICALZEBRA: rk Identity Point Panic in Transaction VerificationEPSS 0.5%CVE-2026-40881MEDIUMZebra: addr/addrv2 Deserialization Resource ExhaustionEPSS 0.5%CVE-2026-40880HIGHZebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip BlocksEPSS 0.4%CVE-2026-52733MEDIUMZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tipEPSS 0.4%CVE-2026-41585MEDIUMZEBRA: Denial of Service via Interrupted JSON-RPC Requests from Authenticated ClientsEPSS 0.4%CVE-2026-44500MEDIUMZEBRA: Allocation Amplification in Inbound Network DeserializersEPSS 0.4%CVE-2026-34377HIGHZebra has a Consensus Failure due to Improper Verification of V5 TransactionsEPSS 0.4%CVE-2026-44498CRITICALZEBRA: Block Validator Undercounts Coinbase and P2SH SigopsEPSS 0.4%CVE-2026-54496CRITICALMissing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundnessEPSS 0.3%