What is CVE-2026-52735?
CVE-2026-52735 affects ZEBRA, a Zcash node written in Rust, in versions prior to 4.5.0. The vulnerability allows Zebra to accept a block that zcashd would reject because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcodes. Affected users should upgrade to version 4.5.0 or later immediately.
Azərbaycanca: CVE-2026-52735 ZEBRA Zcash node-un 4.5.0 versiyasından əvvəlki versiyalarına təsir edir. Bu boşluq Zebra-nın, zcashd tərəfindən rədd edilən bir bloku, əlil opcode-dan sonra gələn imza opcode-larını düzgün saymadığı üçün qəbul etməsinə imkan verir. Təsirə məruz qalan istifadəçilər dərhal 4.5.0 və ya daha yuxarı versiyaya yeniləməlidir.
FAQ2
What does CVE-2026-52735 affect?
This vulnerability affects ZEBRA, a Zcash node written in Rust, in versions prior to 4.5.0.
What is the root cause of CVE-2026-52735?
The vulnerability is caused by the P2SH signature-operation counter undercounting redeem scripts that contain a disabled opcode followed by signature opcodes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.