Improper Following of Specification by Caller Affecting zebra-script package, versions <6.0.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-ZEBRASCRIPT-16624669
  • published10 May 2026
  • disclosed7 May 2026
  • creditsangsoo-osec, defuse

Introduced: 7 May 2026

New CVE NOT AVAILABLE CWE-354  (opens in a new tab)
CWE-573  (opens in a new tab)

How to fix?

Upgrade zebra-script to version 6.0.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Following of Specification by Caller due to improper validation in the transparent signature verification process. An attacker can cause consensus divergence between nodes by crafting a malformed V5 transparent transaction with more inputs than outputs and submitting it to the network.

CVSS Base Scores

version 4.0
version 3.1