Skip to content

Zebra 4.4.1

Choose a tag to compare

@github-actions github-actions released this 04 May 20:14
1ec1078

This release fixes one critical security issue. We recommend node operators update to 4.4.1.

Security

  • Reject V5 transparent inputs signed with SIGHASH_SINGLE (or SIGHASH_SINGLE|ANYONECANPAY) when the input has no transparent output at the same index (GHSA-pvmv-cwg8-v6c8). Follow-up to GHSA-cwfq-rfcr-8hmp.

Thanks to @sangsoo-osec, @zmanian, and @fivelittleducks for reporting the issue.