{"id":"CVE-2026-40880","aliases":["GHSA-xvj8-ph7x-65gf"],"url":"https://o3.security/vulnerability/CVE-2026-40880","summary":"Zebra: Cached Mempool Verification Bypasses Consensus Rules for Ahead-of-Tip Blocks","details":"ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction verification cache could allow a malicious miner to induce a consensus split. By carefully submitting a transaction that is valid for height H+1 but invalid for H+2 and then mining that transaction in a block at height H+2, a miner could cause vulnerable Zebra nodes to accept an invalid block, leading to a consensus split from the rest of the Zcash network. This vulnerability is fixed in zebrad version 4.3.1 and zebra-consensus version 5.0.2.","published":"2026-04-21T19:18:22.657Z","modified":"2026-08-07T11:31:00.392835135Z","cvss":null,"epss":{"score":0.00261,"percentile":0.17664,"asOf":"2026-08-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"zebra-consensus","fixedVersion":"5.0.2"},{"ecosystem":"crates.io","name":"zebrad","fixedVersion":"4.3.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40880.json"},{"type":"ADVISORY","url":"https://github.com/ZcashFoundation/zebra/security/advisories/GHSA-xvj8-ph7x-65gf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40880"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:00.392835135Z"}}