Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of failing. Attackers can craft V5 transactions with fewer outputs than inputs that Zebra accepts and templates via… | |
| Aplazada | Media (6.3) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 4.5.0 contains an uncontrolled resource consumption vulnerability that allows remote P2P peers to exhaust blocking-pool threads by sending oversized block locator vectors. Attackers can send getblocks or getheaders messages with up to 65,535 locator hashes, triggering per-hash chain lookups that degrade… | |
| Aplazada | Alta (8.3) | — | — | ZebradAIZebra ScriptAI | 2/10/2026 | 2/10/2026 | Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network… | |
| Aplazada | Alta (7.1) | — | — | Zcashfoundation ZebraAIZfnd ZebradAI | 2/10/2026 | 2/10/2026 | ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort… | |
| Aplazada | Media (6.9) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the next block hash cause a zero-length sync sample, making the /ready endpoint return 200 OK while the node… | |
| Aplazada | Alta (8.7) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before… | |
| Aplazada | Alta (8.7) | — | — | ZebradAIZebra ScriptAI | 2/10/2026 | 2/10/2026 | Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold… | |
| Aplazada | Media (6.9) | — | — | ZebradAI | 2/10/2026 | 2/10/2026 | Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool… | |
| Aplazada | Media (6.9) | — | — | Zcash Foundation ZebraAI | 2/10/2026 | 2/10/2026 | The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the block's -1 confirmations sentinel is converted to u32 with .expect(), aborting the process. Remote unauthenticated attackers, directly or through lightwalletd, can… | |
| Aplazada | Alta (8.2) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. Attackers can deliver a coinbase-malleated block sharing a canonical block's hash before it propagates, causing the next… | |
| Aplazada | Alta (8.2) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can mine or seed the mempool with roughly 26,000 minimal single-input transactions in one block,… | |
| Aplazada | Media (6.9) | — | — | Zcash Foundation ZebraAI | 2/10/2026 | 2/10/2026 | ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without being misbehavior-scored. Attackers can repeatedly push invalid proofs into the shared halo2 batch verifier, forcing… | |
| Aplazada | Media (6.3) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 6.1.0 contains an incorrect calculation vulnerability in its ZIP-317 block template selector that omits header and transaction-count size from the block budget. Attackers can place valid selectable transactions in a victim miner's mempool to shape templates into oversized blocks, causing rejection and… | |
| Aplazada | Alta (8.7) | — | — | ZebradAI | 2/10/2026 | 2/10/2026 | Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying… | |
| Aplazada | Alta (8.7) | — | — | ZebradAI | 2/10/2026 | 2/10/2026 | The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can… | |
| Aplazada | Media (6.9) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers can send a contextually invalid block sharing an honest block's header hash, causing Request::KnownBlock to skip the honest block… | |
| Aplazada | Media (6.9) | — | — | ZebraAI | 2/10/2026 | 2/10/2026 | Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step wrongly downcasts RouterError to VerifyBlockError and discards the score, so attackers can repeatedly force block download and… | |
| Aplazada | Media (6.3) | — | — | ZebradAI | 2/10/2026 | 2/10/2026 | Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that… | |
| Aplazada | Alta (7.5) | 0.61% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node using the default Linux dual-stack listener configuration. The handshake path canonicalized an IPv4-mapped IPv6 PeerSocketAddr such as ::ffff:127.0.0.1 to plain IPv4 before… | |
| Aplazada | Media (5.9) | 0.52% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transaction in a non-finalized parent block and its child. In zebra-state/src/service/non_finalized_state/chain.rs, Chain::push originally inserted the transaction hash into… | |
| Aplazada | Media (6.9) | 0.51% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one address can permanently halt Zebra nodes. In zebra-state/src/service/finalized_state/zebra_db/transparent.rs, the finalized-state writer originally applied every newly… | |
| Aplazada | Media (5.3) | 0.26% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlocks request with a small two-hash inventory and then serve a syntactically valid block whose coinbase height is far above the local chain tip. In… | |
| Aplazada | Alta (8.7) | 0.61% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block body against the valid canonical body for the same block header hash. ZIP-244 permits the attacker to mutate coinbase scriptSig authentication data while retaining the… | |
| Aplazada | Crítica (9.3) | 0.51% | — | ZebraAIElectriccoin ZcashdAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcodes. In zebra-script/src/lib.rs, p2sh_input_sigop_count used the pure-Rust… | |
| Aplazada | Media (5.3) | 0.51% | — | ZebraAI | 18/8/2026 | 9/9/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/components/mempool/downloads.rs, Downloads::poll_next removed cancel_handles entries… |