ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the base point without a copy constraint tying it to the actual base, allowing a malicious prover to produce a valid proof for an Orchard Action with an under-constrained base point and bypass the diversified-address-integrity check that binds pk_d, g_d, ivk, the nullifier (nf), and the spend validating key (ak) to the note being spent. This issue is fixed in zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-345"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54496.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.5.0"
}
],
"source": "AFFECTED_FIELD"
}
{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.14.0"
},
{
"fixed": "0.28.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
{
"source": "REFERENCES"
}