| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-452v-w3gx-72wg | Zebra has rk Identity Point Panic in Transaction Verification |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 08 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zfnd
Zfnd zebra-chain Zfnd zebrad |
|
| CPEs | cpe:2.3:a:zfnd:zebra-chain:*:*:*:*:*:rust:*:* cpe:2.3:a:zfnd:zebrad:*:*:*:*:*:rust:*:* |
|
| Vendors & Products |
Zfnd
Zfnd zebra-chain Zfnd zebrad |
|
| Metrics |
cvssV3_1
|
Fri, 08 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" value), however, the orchard crate which is used to verify Orchard proofs would panic when fed a rk with the identity value. Thus an attacker could send a crafted transaction that would make a Zebra node crash. This issue has been patched in zebrad version 4.3.1 and zebra-chain version 6.0.2. | |
| Title | ZEBRA: rk Identity Point Panic in Transaction Verification | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T16:04:49.931Z
Reserved: 2026-04-21T14:15:21.959Z
Link: CVE-2026-41584
Updated: 2026-05-08T16:04:46.090Z
Status : Analyzed
Published: 2026-05-08T15:16:41.240
Modified: 2026-05-08T18:21:13.283
Link: CVE-2026-41584
No data.
OpenCVE Enrichment
Updated: 2026-05-08T18:00:16Z
Github GHSA