The Zcash Foundation releases Zebra 4.4.0, fixing multiple critical consensus security vulnerabilities

robot
Abstract generation in progress

Golden Finance reports that on May 3rd, the Zcash Foundation released Zebra 4.4.0.
It states that this version includes fixes for multiple security vulnerabilities, especially addressing several critical consensus issues, and strongly recommends all node operators upgrade immediately.
Fixes include: resolving a potential denial-of-service vulnerability that could cause nodes to permanently stop discovering new blocks; correcting an issue with insufficient sigops counting in block validators (involving coinbase and P2SH), which could have caused Zebra to accept blocks rejected by zcashd; fixing a consensus split caused by inadequate handling of FFI bridge errors in transparent sighash; and addressing memory amplification risks in inbound network deserialization.
Additionally, this version implements resource limits on the indexer gRPC server and RPC request body size, adds an nTx field in getblock responses to report transaction count, and updates the librustzcash dependency stack to address the RUSTSEC-2026-0105 security risk.

ZEC-0.01%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin