AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-52735.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSCRITICAL / 9.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

### Am I affected You are affected if: 1. You run any version of `zebrad` up to and including `v4.4.1`. 2. Your node validates blocks on mainnet, testnet, or any network where both Zebra and zcashd nodes participate. All default configurations are affected. No feature flags, non-default settings, or special build options are required. ### Summary Zebra's P2SH sigop counter uses a pure-Rust code path that short-circuits on disabled opcodes (such as `OP_CODESEPARATOR`), returning a partial count of zero for any sigops following the disabled opcode. The reference implementation (zcashd) correctly counts through disabled opcodes in its static sigop analysis. This produces a consensus divergence: Zebra accepts blocks that zcashd rejects when the block-wide `MAX_BLOCK_SIGOPS = 20,000` threshold is crossed on one side but not the other. An attacker can exploit this without mining capability. Broadcasting transactions that spend P2SH outputs with malicious redeem scripts is sufficient; any Zebra miner who includes those transactions in a block triggers a chain split between Zebra and zcashd validators. ### Details The P2SH sigop counter at `zebra-script/src/lib.rs:399` calls `script::Code(

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-gf9r-m956-97qx

Open original source · Updated Sep 30, 2026

zebrad has consensus divergence via P2SH sigop undercount in pure-Rust disabled-opcode parser

Source severity: CRITICAL / 9.3

EcosystemPackageAffected rangeFirst patched
rustzebra-script7.0.0
rustzebrad4.5.0

Original records & references

PUBLISHED 2026-07-02T15:43:36-04:00
MODIFIED 2026-09-30T18:55:26-04:00
INGESTED 2026-10-06T11:43:09-04:00