Answer in brief
CVE-2026-104430 records a High severity (CVSS 8.7) vulnerability in Zebra 4.5.0 Consensus Split via P2SH Sigop Overcount. The current sources do not mark it as known exploited. The current feed maps ZcashFoundation/zebra (generic), ZcashFoundation/zebra (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.7. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ZcashFoundation/zebra (generic), ZcashFoundation/zebra (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ZcashFoundation/zebrageneric | >=4.5.0 <4.5.1 | 4.5.1 |
| ZcashFoundation/zebrageneric | >=7.0.0 <7.0.1 | 7.0.1 |
Published upstream
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 2, 2026
Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold multisig redeem scripts so that a block zcashd accepts exceeds Zebra's inflated MAX_BLOCK_SIGOPS count, causing Zebra nodes to reject it and stall off the chain.
Quoted source text, attributed separately from HOL analysis.