What is CVE-2026-52733?
In ZEBRA Zcash node versions prior to 4.5.0, a chain fork can leave stale Sapling and Orchard note-commitment subtree roots in the state due to improper cleanup in `Chain::pop_tip`. Users should upgrade to version 4.5.0 or later.
Azərbaycanca: ZEBRA Zcash node-un 4.5.0-dən əvvəlki versiyalarında chain fork nəticəsində köhnə Sapling və Orchard note-commitment subtree root-ları state-də qala bilər. Bu, `Chain::pop_tip` funksiyasının geri qaytarılan bloku düzgün təmizləməməsi səbəbindən baş verir. İstifadəçilər 4.5.0 və ya daha yuxarı versiyaya yenilənməlidir.
FAQ2
Which versions of ZEBRA Zcash node are affected by CVE-2026-52733?
Versions of ZEBRA Zcash node prior to 4.5.0 are affected by this vulnerability.
What is the root cause of CVE-2026-52733?
The vulnerability occurs because the `Chain::pop_tip` function does not properly clean up rolled-back blocks during a chain fork.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.