{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/consensus-vulnerability/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-104430"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["zebrad (4.5.0)","zebra-script (7.0.0)","zebrad (4.4.0)","zebra-script (6.0.0)"],"_cs_severities":["medium"],"_cs_tags":["consensus-vulnerability","denial-of-service","zebra","blockchain","crypto","network-protocol"],"_cs_type":"advisory","_cs_vendors":["Zebra"],"content_html":"\u003cp\u003eZebra zebrad version 4.5.0 and zebra-script version 7.0.0 contain a critical consensus vulnerability related to how signature operations (sigops) are calculated in P2SH redeem scripts. The software incorrectly uses legacy counting modes instead of the accurate P2SH mode employed by zcashd. Specifically, the implementation overcounts CHECKMULTISIG operations when preceded by OP_1 through OP_16, assigning them a value of 20 sigops. This discrepancy leads to a consensus divergence where Zebra nodes calculate a higher total sigop count for certain transactions than the zcashd reference implementation. This vulnerability allows remote attackers to construct and broadcast specific P2SH multisig spends that exceed Zebra's MAX_BLOCK_SIGOPS threshold while remaining valid within the zcashd network. Consequently, affected Zebra nodes will reject legitimate blocks and stall, effectively removing them from the consensus chain and creating a denial-of-service condition for the node.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in a denial of service for Zebra-based nodes. By broadcasting specifically crafted P2SH transactions, an attacker can force affected nodes to drop out of the network synchronization process, leading to loss of consensus and node stalling. This affects any network deployments relying on these specific versions of Zebra zebrad or zebra-script for block validation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of nodes running vulnerable Zebra software versions. Monitor node logs for repeated block validation failures or synchronization stalls that coincide with unusual multisig transaction activity. Upgrade affected systems to patched versions as soon as they are made available by the maintainers. Review network telemetry for anomalous block broadcast traffic targeting Zebra nodes.\u003c/p\u003e\n","date_modified":"2026-10-02T12:24:33Z","date_published":"2026-10-02T12:24:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-zebra-consensus-divergence/","summary":"An incorrect signature operation count in Zebra zebrad 4.5.0 and zebra-script 7.0.0 causes consensus divergence when processing specific P2SH multisig transactions, potentially leading to a denial-of-service condition for affected nodes.","title":"Consensus Divergence Vulnerability in Zebra zebrad and zebra-script","url":"https://feed.craftedsignal.io/briefs/2026-10-zebra-consensus-divergence/"}],"language":"en","title":"CraftedSignal Threat Feed - Consensus-Vulnerability","version":"https://jsonfeed.org/version/1.1"}