🛡️ CVE-2026-44498 — zebrad
Description
Zebra's Block Validator Undercounts Coinbase and P2SH Sigops
Zebra's block validator undercounts transparent signature operations against the 20000-sigop block limit (MAX_BLOCK_SIGOPS), allowing it to accept blocks that zcashd rejects with bad-blk-sigops. A miner who produces such a block can split the network: Zebra nodes follow the offending chain while zcashd nodes do not.
Two distinct undercounts:
A: Coinbase Hidden Legacy Sigops
zcashd's GetLegacySigOpCount() includes the coinbase input's scriptSig. Zebra's Sigops impl skipped the coinbase input entirely, so up to ~98 sigops (the 100-byte coinbase script length cap, less the height prefix) could be hidden inside the coinbase scriptSig without being charged against the block limit.
B: Aggregate P2SH Sigops.
zcashd's GetP2SHSigOpCount() parses each P2SH input's redeem script with accurate=true and sums those sigops into the block-wide total via ConnectBlock. The check is per-block, not per-transaction, and the limit applies regardless of who mines the offending block — a miner just needs to include enough P2SH-spending transactions whose redeem scripts together exceed 20000 sigops. Zebra computed P2SH sigops only on the mempool-acceptance path (used for ZIP-317 weighting) and never accumulated them during block validation. A block whose aggregate redeem-script sigops exceed 20000 (e.g. 1334 P2SH spends × 15 sigops = 20010) would be accepted by Zebra and rejected by zcashd.
Patches
Fixed in this release: https://github.com/ZcashFoundation/zebra/releases/tag/v4.4.0.
Workarounds
None. Operators relying on Zebra for consensus should upgrade.
Resources
MAX_BLOCK_SIGOPSconstant inherited from Bitcoin via the Zcash protocol spec's §7.6 catch-all "Other rules inherited from Bitcoin", tracked for explicit documentation in [zcash/zips#568](https://github.com/zcash/zips/issues/568).zcashdGetLegacySigOpCount: <https://github.com/zcash/zcash/blob/v6.11.0/src/main.cpp#L826-L836>zcashdGetP2SHSigOpCount: <https://github.com/zcash/zcash/blob/v6.11.0/src/main.cpp#L840-L852>zcashdConnectBlockaggregates per-tx sigops and compares againstMAX_BLOCK_SIGOPS.
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality none, integrity high, availability none.
Affected software
CVE-2026-44498 is recorded against 1 package.
- zebrad
Timeline and source
Published on 7 May 2026 and last revised on 17 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Package)
github.com (Web)
Details
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| zebrad | — | — |
References
Similar Threats
- Unknown CVE-2026-52731
- Unknown CVE-2026-52732
- Unknown CVE-2026-52733
- Unknown CVE-2026-52734
- Unknown CVE-2026-52738
More CVE 2026 advisories
Browse all of CVE 2026 in the advisory index.
Exploit Protection
Are you running zebrad?
CVE-2026-44498 carries CVSS 9.5 Critical rating. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.
Check My Site For CVE-2026-44498 →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.