CVE-2026-52732
Description
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Zebra's inbound mempool download and verification pipeline. In zebrad/src/components/mempool/downloads.rs, the bounded queue was shared globally without per-peer accounting, while peer identity was not carried through Gossip and FullQueue responses were mapped to Response::Nil instead of reaching overload disconnection handling. An attacker can advertise fake transaction identifiers and remain silent so each task holds a slot until TRANSACTION_DOWNLOAD_TIMEOUT, then periodically refill the queue as slots expire. While saturated, honest peer transactions and local sendrawtransaction requests are rejected with MempoolError::FullQueue, although block validation and synchronization continue. This issue is fixed in version 4.5.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
zebradcrates.io | < 4.5.0 | 4.5.0 |
Affected products
1- Range: <4.5.0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-4fc2-h7jh-287cghsaADVISORY
- github.com/ZcashFoundation/zebra/blob/d4cd662c716382f6397d2a730148025a1ca79fec/zebrad/src/components/mempool/downloads.rsghsaWEB
- github.com/ZcashFoundation/zebra/security/advisories/GHSA-4fc2-h7jh-287cnvdWEB
- github.com/ZcashFoundation/zebra/commit/1440b43ca7df59aca948090d45117557b217a6cdnvd
- github.com/ZcashFoundation/zebra/releases/tag/v4.5.0nvd
News mentions
0No linked articles in our index yet.