Technology · crates.io
zebrad (crates.io) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 26 vulnerabilities in zebrad (crates.io): 0 in the last 7 days and 14 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-52829, was published on 18 August 2026.
- Last 7 days
- 0
- Last 90 days
- 14
- Critical, all time
- 6
- Exploited in the wild
- 0
About zebrad (crates.io)
The primary Zcash node implementation written in Rust.
Latest zebrad (crates.io) vulnerabilities
- CVE-2026-52829: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically…highCVSS 7.5EPSS 0.6%
- CVE-2026-52739: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing…mediumCVSS 5.9EPSS 0.5%
- CVE-2026-52738: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of…mediumCVSS 6.9EPSS 0.5%
- CVE-2026-52737: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's…mediumCVSS 5.3EPSS 0.3%
- CVE-2026-52736: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node…highCVSS 8.7EPSS 0.6%
- CVE-2026-52735: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the…criticalCVSS 9.3EPSS 0.5%
- CVE-2026-52734: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download…mediumCVSS 5.3EPSS 0.5%
- CVE-2026-52733: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-52732: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25…mediumCVSS 5.3EPSS 0.5%
- CVE-2026-52731: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint…mediumCVSS 6.5EPSS 0.5%
- CVE-2026-54496: Zcash Orchard Action circuit soundness vulnerability in halo2_gadgetscriticalCVSS 9.3
- Zcash Foundation Zebra resource exhaustion in P2P codeclowCVSS 3.7
- ZcashFoundation zebrad denial of service in z_listunifiedreceiversmediumCVSS 6.5
- Zcash Zebra CPU amplification in getblocks and getheaders handlerslowCVSS 3.7
- CVE-2026-44499: Zcash Foundation Zebra Denial of Service in block discovery pipelinehighCVSS 8.7EPSS 0.1%
- Zcash Zebra consensus divergence in SIGHASH_SINGLE handlingcriticalCVSS 9.2
- CVE-2026-44497: Zcash Foundation Zebra consensus divergence in sighash handlingcriticalCVSS 9.1
- CVE-2026-44500: ZcashFoundation Zebra denial of service via allocation amplificationmediumCVSS 5.3
- CVE-2026-44498: Zcash Zebra consensus failure via sigop undercounting in block validatorhighCVSS 7.5
- CVE-2026-41583: Zcash Foundation Zebra consensus divergence in sighash handlingcriticalCVSS 9.1
- CVE-2026-41585: Zebra Vulnerable to Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clientsmedium
- CVE-2026-41584: Zebra has rk Identity Point Panic in Transaction Verificationcritical
- CVE-2026-40881: Zcash Foundation Zebra resource exhaustion in addr message deserializationmediumEPSS 0.1%
- CVE-2026-40880: Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blockshigh
- CVE-2026-34377: ZcashFoundation Zebra consensus split via invalid V5 authorization datahighCVSS 8.1EPSS 0.3%
Most severe zebrad (crates.io) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-52735: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the…criticalCVSS 9.3EPSS 0.5%
- CVE-2026-54496: Zcash Orchard Action circuit soundness vulnerability in halo2_gadgetscriticalCVSS 9.3
- Zcash Zebra consensus divergence in SIGHASH_SINGLE handlingcriticalCVSS 9.2
- CVE-2026-44497: Zcash Foundation Zebra consensus divergence in sighash handlingcriticalCVSS 9.1
- CVE-2026-41583: Zcash Foundation Zebra consensus divergence in sighash handlingcriticalCVSS 9.1
- CVE-2026-41584: Zebra has rk Identity Point Panic in Transaction Verificationcritical
- CVE-2026-52736: ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node…highCVSS 8.7EPSS 0.6%
- CVE-2026-44499: Zcash Foundation Zebra Denial of Service in block discovery pipelinehighCVSS 8.7EPSS 0.1%
- CVE-2026-34377: ZcashFoundation Zebra consensus split via invalid V5 authorization datahighCVSS 8.1EPSS 0.3%
- CVE-2026-34202: ZcashFoundation Zebra remote denial of service via crafted V5 transactionshighCVSS 7.5EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 3 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 1 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 10 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/zebrad.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "zebrad (crates.io) vulnerabilities", https://junglewise.ai/threats/technologies/zebrad, 26 September 2026.