CVE Feed

    Dashboard / CVE / CVE-2026-44500

    CVE-2026-44500

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced. An unauthenticated or post-handshake peer could therefore force the node to preallocate and parse for orders of magnitude more data than the protocol intended, across headers messages, equihash solutions in block headers, Sapling spend vectors in V5/V4 transactions, and coinbase script bytes in blocks. This issue has been patched in zebrad version 4.4.0, zebra-chain version 7.0.0, and zebra-network version 6.0.0.

    Published:May 8, 2026
    Last Modified:May 8, 2026
    EPS:May 8, 2026
    EPSS Score:
    CVSS Score:5.3

    Affected Products

    Vendor
    Zcashfoundation
    Product
    Zebra
    Vendor
    Zfnd
    Product
    Zebra-chain
    Vendor
    Zfnd
    Product
    Zebra-network
    Vendor
    Zfnd
    Product
    Zebrad

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High