<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:51:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278307</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278307</link>
      <description>EUVD-2026-278307</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278307</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34202</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34202</link>
      <description>&lt;p&gt;ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra&amp;#39;s transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation. This issue has been patched in zebrad version 4.3.0 and zebra-chain version 6.0.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra&amp;#39;s transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation. This issue has been patched in zebrad version 4.3.0 and zebra-chain version 6.0.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34202</guid>
    </item>
    <item>
      <title>GHSA-qp6f-w4r3-h8wg — Zebra node crash — V5 transaction hash panic (P2P reachable)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qp6f-w4r3-h8wg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: zebrad, crates.io: zebra-chain&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;# Remote Denial of Service via Crafted V5 Transactions&lt;/p&gt;
&lt;p&gt;## Summary
A vulnerability in Zebra&amp;#39;s transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation.&lt;/p&gt;
&lt;p&gt;## Severity
**Critical** - This is a Remote Denial of Service (DoS) that requires no authentication and can be triggered by a single network message.&lt;/p&gt;
&lt;p&gt;## Affected Versions
All Zebra versions supporting V5 transactions (Network Upgrade 5 and later) prior to **version 4.3.0**.&lt;/p&gt;
&lt;p&gt;## Description
The vulnerability stems from Zebra lazily validating transaction fields that are eagerly validated in the librustzcash parsing logic used when Zebra computes transaction ids and auth digests for V5 transactions where Zebra panics if those computations fail.&lt;/p&gt;
&lt;p&gt;`PushTransaction` messages with malformed V5 transactions are successfully deserialized as the zebra-chain `Transaction` type by the network codec, but when Zebra converts those transactions into internal types to compute the TxID expecting it to succeed, it triggers a panic/crash.&lt;/p&gt;
&lt;p&gt;An attacker can trigger this crash by sending a single crafted `tx` message to a Zebra node&amp;#39;s public P2P port. The same issue can be triggered via the `sendrawtransaction` RPC method.&lt;/p&gt;
&lt;p&gt;## Impact
**Remote Denial of Service**
* **Attack Vector:** Remote, unauthenticated.
* **Effect:** Immediate crash of the Z…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: zebrad, crates.io: zebra-chain&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;# Remote Denial of Service via Crafted V5 Transactions&lt;/p&gt;
&lt;p&gt;## Summary
A vulnerability in Zebra&amp;#39;s transaction processing logic allows a remote, unauthenticated attacker to cause a Zebra node to panic (crash). This is triggered by sending a specially crafted V5 transaction that passes initial deserialization but fails during transaction ID calculation.&lt;/p&gt;
&lt;p&gt;## Severity
**Critical** - This is a Remote Denial of Service (DoS) that requires no authentication and can be triggered by a single network message.&lt;/p&gt;
&lt;p&gt;## Affected Versions
All Zebra versions supporting V5 transactions (Network Upgrade 5 and later) prior to **version 4.3.0**.&lt;/p&gt;
&lt;p&gt;## Description
The vulnerability stems from Zebra lazily validating transaction fields that are eagerly validated in the librustzcash parsing logic used when Zebra computes transaction ids and auth digests for V5 transactions where Zebra panics if those computations fail.&lt;/p&gt;
&lt;p&gt;`PushTransaction` messages with malformed V5 transactions are successfully deserialized as the zebra-chain `Transaction` type by the network codec, but when Zebra converts those transactions into internal types to compute the TxID expecting it to succeed, it triggers a panic/crash.&lt;/p&gt;
&lt;p&gt;An attacker can trigger this crash by sending a single crafted `tx` message to a Zebra node&amp;#39;s public P2P port. The same issue can be triggered via the `sendrawtransaction` RPC method.&lt;/p&gt;
&lt;p&gt;## Impact
**Remote Denial of Service**
* **Attack Vector:** Remote, unauthenticated.
* **Effect:** Immediate crash of the Z…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qp6f-w4r3-h8wg</guid>
    </item>
  </channel>
</rss>
