CVE-2026-104437
Last modified
CVE-2026-104437 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects..
Description
Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via getblocktemplate, producing blocks zcashd rejects.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ZcashFoundation | zebra | < 4.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104437?
How severe is CVE-2026-104437?
How do I fix CVE-2026-104437?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104431Zebra before 6.0.0 contains a denial of service vulnerabilit…7.5
- CVE-2026-104432Zebra before 6.3.0 contains an improper exceptional conditio…5.3
- CVE-2026-104433Mooncake transfer engine before 0.3.12 contains an out-of-bo…7.5
- CVE-2026-104434ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad befo…6.5
- CVE-2026-104435Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a …7.4
- CVE-2026-104436Zebra before 4.5.0 contains an uncontrolled resource consump…3.7
- CVE-2026-104438YesWiki before 4.6.7 contains a missing authorization vulner…5.3
- CVE-2026-104439YesWiki before 4.6.7 contains a user enumeration vulnerabili…5.3
- CVE-2026-104440YesWiki before 4.6.7 contains a blind server-side request fo…5.3
- CVE-2026-104441YesWiki before 4.6.7 contains an unauthenticated server-side…5.3
- CVE-2026-104442YesWiki before 4.6.7 contains an unauthenticated server-side…5.8
- CVE-2026-104443YesWiki before 4.6.7 contains an empty-filter scope bypass i…8.1
Are you affected by CVE-2026-104437?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
