Zcash Foundation Issues High-Severity Security Alert for Zebra 6.4.0 and 6.4.1
The Zcash Foundation is urging Zebra node operators running versions 6.4.0 or 6.4.1 to upgrade immediately to patch a high-severity vulnerability that could allow remote node crashes.
By T. Noe · ZecZcash News Team

The Zcash Foundation has issued a security alert regarding a high-severity vulnerability in Zebra node software. Operators running Zebra versions 6.4.0 or 6.4.1 are urged to upgrade immediately to version 6.4.2.
The vulnerability could allow any peer on the network to remotely crash an affected Zebra node by sending a single malicious network message. Versions 6.4.0 and 6.4.1 have been recalled in response.
Zebra 6.3.0 and earlier versions are not affected by this issue. The vulnerability poses no risk to funds or network consensus. The flaw was discovered through continuous fuzzing and has been fixed in Zebra 6.4.2.
Key Facts
- Affected versions
- Zebra 6.4.0 and 6.4.1
- Fixed in
- Zebra 6.4.2
- Unaffected versions
- Zebra 6.3.0 and earlier
- Impact
- Remote crash via malicious network message



