According to Zcash Foundation, Zebra 4.4.0 was released today, fixing multiple consensus-level security vulnerabilities and urging all node operators to upgrade immediately. The vulnerabilities include a denial-of-service flaw that could halt block discovery permanently, sigops counting errors causing consensus disagreement, transparent transaction signature hash handling issues, and memory allocation amplification attack risks.
The foundation stated that some vulnerabilities could cause Zebra nodes to accept blocks rejected by zcashd, potentially triggering chain forks. Without timely updates, nodes risk block discovery interruption, consensus divergence, and resource consumption amplification, with no alternative mitigation available.