Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-ww9q-8r59-xv46
  • crates.io/halo2_gadgets
  • crates.io/orchard
  • crates.io/zcash_primitives
  • crates.io/zebrad
Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness 06 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-63wg-wjjj-7cp8
  • crates.io/zebra-network
  • crates.io/zebrad
Zebra Address Book Aborted by IPv4-Mapped Mempool Misbehavior Update 02 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-65jj-fmw8-468q
  • crates.io/zebrad
zebrad has unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention 02 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-2gf8-q9rr-jq3h
  • crates.io/zebra-state
  • crates.io/zebrad
zebrad has persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip 02 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-hhm7-qrv5-h4r6
  • crates.io/zebra-state
  • crates.io/zebrad
Zebra: Repeated Non-Finalized Shielded Transaction Aborts Zebra Before Duplicate-Nullifier Rejection 02 Jul
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-w834-cf6p-9m9w
  • crates.io/zebra-state
  • crates.io/zebrad
Zebra: Finalized address balance credit-first overflow on consensus-valid blocks 02 Jul
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-gvjc-3w7c-92jx
  • crates.io/zebra-consensus
  • crates.io/zebrad
Zebra has sync restart poisoning from single unauthenticated peer via above-lookahead block 02 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-gf9r-m956-97qx
  • crates.io/zebra-script
  • crates.io/zebrad
zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser 02 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-4m69-67m6-prqp
  • crates.io/zebra-state
  • crates.io/zebrad
Zebra has block suppression via NU5 same-header body poisoning of sent-hash cache 02 Jul
  • Fix available
  • Severity - 8.7 (High)
GHSA-h72h-ppcx-998p
  • crates.io/zebra-network
  • crates.io/zebrad
Zebra has pre-handshake buffer capacity reservation based on attacker-claimed body length 02 Jul
  • Fix available
  • Severity - 3.7 (Low)
GHSA-4fc2-h7jh-287c
  • crates.io/zebrad
zebrad has mempool transaction admission denial via single-peer inbound queue saturation 02 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-c8w6-x74f-vmg3
  • crates.io/zebra-rpc
  • crates.io/zebrad
zebrad vulnerable to full node denial of service via crafted Sapling receiver in z_listunifiedreceivers 02 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-443g-gwgp-49x4
  • crates.io/zebra-chain
  • crates.io/zebrad
zebrad vulnerable to getblocks/getheaders locator CPU amplification via uncapped vector length 02 Jul
  • Fix available
  • Severity - 3.7 (Low)
GHSA-qv2r-v3mx-f4pf
  • crates.io/zebra-rpc
  • crates.io/zebrad
zebrad has full node denial of service via non-ASCII LongPollId in getblocktemplate 02 Jul
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-h9hm-m2xj-4rq9
  • crates.io/zebrad
Zebra has Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning 08 May
  • Fix available
  • Severity - 8.7 (High)
GHSA-pvmv-cwg8-v6c8
  • crates.io/zebra-script
  • crates.io/zebrad
Zebra v4.4.0 still accepts V5 SIGHASH_SINGLE without a corresponding output 08 May
  • Fix available
  • Severity - 9.3 (Critical)