VDB
Sign up

package

crates.io/zebrad

pkg:crates.io/zebrad

LOW3.7crates.io
GHSA-443g-gwgp-49x4

zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length

Modified: 7/2/2026

MEDIUM6.5crates.io
GHSA-c8w6-x74f-vmg3

zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers

Modified: 7/2/2026

CRITICALcrates.io
GHSA-cwfq-rfcr-8hmp

Zebra's Transparent SIGHASH_SINGLE Handling Diverges from zcashd for Corresponding Outputs

Modified: 5/21/2026

LOW3.7crates.io
GHSA-h72h-ppcx-998p

Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length

Modified: 7/2/2026

CRITICALcrates.io
GHSA-pvmv-cwg8-v6c8

Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output

Modified: 5/22/2026

CRITICAL9.3crates.io
GHSA-ww9q-8r59-xv46· CVE-2026-54496

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Modified: 7/6/2026