Zcash Foundation releases Zebra 4.4.0, fixing multiple critical consensus security vulnerabilities

robot
Abstract generation in progress

ME News Report, May 2 (UTC+8), the Zcash Foundation released Zebra 4.4.0. It states, “This version includes fixes for multiple security vulnerabilities, especially addressing several critical consensus issues. All node operators are strongly advised to upgrade immediately.” The fixes include: resolving a denial-of-service vulnerability that could cause nodes to permanently stop discovering new blocks; correcting an issue with insufficient sigops counting in block validators (involving coinbase and P2SH), which could have caused Zebra to accept blocks rejected by zcashd; fixing a transparency sighash consensus divergence caused by inadequate FFI bridging error handling; and addressing memory amplification risks during inbound network deserialization. Additionally, this version implements resource limits on the indexer gRPC server and RPC request body size, adds an nTx field in getblock responses to report transaction count, and updates the librustzcash dependency stack to patch the RUSTSEC-2026-0105 security risk. (Source: Foresight News)

ZEC9.69%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin