zebrad is vulnerable to Incorrect Calculation
93
Critical Risk
Zebra's block validation counts P2SH redeem-script signature operations with the legacy counting mode instead of the accurate P2SH mode. A low-threshold multisig redeem script is over-counted, inflating a block's signature-operation total. When the inflated total crosses the block-wide sigop limit that the true count does not, the node rejects a block that the rest of the network accepts, stalling the node and splitting it from the canonical chain. The fix restores accurate P2SH sigop counting.
You are affected if you are using a version that falls within the vulnerable range and your node validates blocks on a network shared with other Zcash consensus implementations.
zebrad is vulnerable to Incorrect Calculation in versions 4.5.0 - 4.5.0.
Upgrade the zebrad and/or the zebra-script library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant