What is CVE-2026-52731?
CVE-2026-52731 is a vulnerability found in ZEBRA, a Zcash node written in Rust. Before version 4.5.0, an attacker authenticated to an enabled RPC endpoint can terminate the zebrad process by providing a getblocktemplate LongPollId containing multi-byte UTF-8 characters. Upgrading to version 4.5.0 or later is strongly recommended to mitigate this issue.
Azərbaycanca: CVE-2026-52731, Rust dilində yazılmış Zcash nodu olan ZEBRA-da aşkar edilmiş boşluqdur. 4.5.0 versiyasından əvvəl, aktivləşdirilmiş RPC endpoint-ə autentifikasiya olunmuş təcavüzkar, `getblocktemplate` sorğusunda çoxbaytlı UTF-8 simvollardan ibarət `LongPollId` göndərərək `zebrad` prosesini dayandıra bilər. Təsirə məruz qalmamaq üçün dərhal 4.5.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
FAQ2
Does exploiting CVE-2026-52731 require the attacker to be authenticated?
Yes, an attacker must be authenticated to an enabled RPC endpoint in order to exploit CVE-2026-52731.
What action is recommended to mitigate CVE-2026-52731?
To mitigate CVE-2026-52731, it is recommended to upgrade the ZEBRA node to version 4.5.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.