CVE-2026-52736 | ZcashFoundation Zebra up to 4.4.x Zebra State service.rs queue_and_commit_to_non_finalized_state race condition
A vulnerability has been found in ZcashFoundation Zebra up to 4.4.x and classified as problematic. This impacts the function queue_and_commit_to_non_finalized_state of the file zebra-state/src/service.rs of the component Zebra State. The manipulation leads to race condition.
This vulnerability is documented as CVE-2026-52736. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.VulDB Recent EntriesRead More