What is CVE-2026-52732?
CVE-2026-52732 is a vulnerability in the ZEBRA Zcash node (prior to version 4.5.0) where an unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in the mempool download and verification pipeline, leading to a Denial of Service. Users must upgrade to version 4.5.0 or later to mitigate this issue.
Azərbaycanca: CVE-2026-52732 ZEBRA Zcash node-da autentifikasiya olunmamış P2P peer-in bütün 25 inbound mempool yükləmə və yoxlama slotlarını ələ keçirməsinə imkan verən boşluqdur. Təsir 4.5.0-dan əvvəlki versiyalara aiddir; şəbəkə resurslarının mono-polizasiya edilərək xidmət pozulmasına (Denial of Service) səbəb ola bilər. İstifadəçilər dərhal 4.5.0 və ya daha yuxarı versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which functional area of the ZEBRA Zcash node is affected by CVE-2026-52732?
This vulnerability affects all 25 MAX_INBOUND_CONCURRENCY slots in the mempool download and verification pipeline.
What version should users upgrade to in order to mitigate CVE-2026-52732?
Users must immediately upgrade the ZEBRA Zcash node to version 4.5.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.