What is CVE-2026-52737?
CVE-2026-52737 affects ZEBRA Zcash node versions prior to 4.5.0. An unauthenticated P2P peer can respond to an outbound `getblocks` request with a syntactically valid block containing a `coinbase height` far above the local chain tip. Users should upgrade to ZEBRA version 4.5.0 or later.
Azərbaycanca: CVE-2026-52737 ZEBRA Zcash node-un 4.5.0 versiyasından əvvəlki versiyalarına təsir edir. Təsdiqlənməmiş P2P peer, `getblocks` sorğusuna xüsusi hazırlanmış cavab göndərərək lokal chain-dən çox yüksək `coinbase height`-ə malik sintaktik düzgün blok təqdim edə bilər. İstifadəçilər ZEBRA-nı 4.5.0 və ya daha yeni versiyaya yeniləməlidir.
FAQ2
Which product is affected by CVE-2026-52737?
CVE-2026-52737 affects ZEBRA Zcash node versions prior to 4.5.0.
Is authentication required to exploit CVE-2026-52737?
No, an unauthenticated P2P peer can exploit this vulnerability by sending a specially crafted response to a `getblocks` request.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.