Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.21% | — | ZebradAIZebra ScriptAI | 2/10/2026 | 2/10/2026 | Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. Attackers can broadcast crafted V5 transactions with more inputs than outputs that Zebra accepts but zcashd rejects, causing a network… | |
| Aplazada | Alta (7.1) | 0.31% | — | Zcashfoundation ZebraAIZfnd ZebradAI | 2/10/2026 | 2/10/2026 | ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invalid Jubjub points. Authenticated RPC clients can submit such an address to abort… | |
| Aplazada | Alta (8.7) | 0.41% | — | ZebradAIZebra ScriptAI | 2/10/2026 | 2/10/2026 | Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by OP_1 through OP_16 as 20 sigops and causing a consensus divergence. Remote attackers can broadcast P2SH spends using low-threshold… | |
| Aplazada | Media (6.9) | 0.30% | — | ZebradAI | 2/10/2026 | 2/10/2026 | Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued without the sending peer recorded as their source. A remote inbound peer can push many unique transactions to occupy a disproportionate share of mempool… | |
| Aplazada | Alta (8.7) | 0.34% | — | ZebradAI | 2/10/2026 | 2/10/2026 | Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid Halo2 proofs. Attackers can flood the shared unprioritized Halo2 verification queue with zero-fee transactions carrying… | |
| Aplazada | Alta (8.7) | 0.18% | — | ZebradAI | 2/10/2026 | 2/10/2026 | The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too far behind the tip before consensus validation, without penalizing the supplying peer. Because V5 transaction IDs exclude the scriptSig, a malicious peer can… | |
| Aplazada | Media (6.3) | 0.13% | — | ZebradAI | 2/10/2026 | 5/10/2026 | Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that… | |
| Aplazada | Crítica (9.3) | 0.32% | — | ZebradAIHalo2 GadgetsAIZcash PrimitivesAIOrchardproject OrchardAI+1 | 17/7/2026 | 17/7/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying… | |
| Analizada | Media (5.3) | 0.41% | — | Zfnd Zebra-chainZfnd Zebra-networkZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus… | |
| Analizada | Crítica (9.2) | 0.38% | — | Zfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who produces such a block can split the… | |
| Analizada | Crítica (9.3) | 0.30% | — | Zfnd Zebra-scriptZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 introduced a separate issue due to insufficient error handling of the case where the sighash type is invalid, during sighash computation. Instead of returning an error, the… | |
| Analizada | Media (6.9) | 0.43% | — | Zfnd Zebra-rpcZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to cause a Zebra node to crash by disconnecting before the request body is fully… | |
| Analizada | Crítica (9.2) | 0.46% | — | Zfnd Zebra-chainZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a rk field which is a randomized validating key and also an elliptic curve point. The Zcash specification allows the field to be the identity (a "zero" value), however, the… | |
| Analizada | Crítica (9.3) | 0.47% | — | Zfnd Zebra-scriptZfnd Zebrad | 8/5/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rule that restricted the possible values of sighash hash types for V5 transactions which were enabled in the NU5 network upgrade. Zebra nodes… | |
| Analizada | Media (6.3) | 0.46% | — | Zfnd Zebra-networkZfnd Zebrad | 21/4/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 messages, which contain vectors of addresses, Zebra would fully deserialize them up to a maximum length (over 233,000) that was derived from the 2 MiB message size limit.… | |
| Analizada | Alta (7.2) | 0.44% | — | Zfnd Zebra-consensusZfnd Zebrad | 21/4/2026 | 17/6/2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and… |