Peer-to-Peer Vulnerability in ZEBRA Zcash Node Affects Data Synchronization
CVE-2026-52737
5.3MEDIUM
What is CVE-2026-52737?
The ZEBRA Zcash node, written in Rust, has a vulnerability that permits a malicious unauthenticated peer to respond to outbound getblocks or FindBlocks requests with a small two-hash inventory. This malicious behavior can culminate in serving a block with a coinbase height significantly surpassing the local chain tip, triggering a sequence that cancels legitimate downloads and leads to prolonged synchronization delays. The issue resulted in an indefinite cycle of degradation in synchronization efficiency, without corrupting the local state. This vulnerability is resolved in version 4.5.0.
Affected Version(s)
zebra < 4.5.0
zebra-consensus < 7.0.0
