← Vulnerability feed

Vulnerability record · CVE-2026-44500 · published 8 May 2026

CVE-2026-44500: Zfnd zebra-chain allocation without limits vulnerability

Zfnd · Zebra Chain

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced. An unauthenticated or post-handshake peer could therefore force the node to preallocate and parse for orders of magnitude more data than the protocol intended, across headers messages, equihash solutions in block headers, Sapling spend vectors in V5/V4 transactions, and coinbase script bytes in blocks. This issue has been patched in zebrad version 4.4.0, zebra-chain version 7.0.0, and zebra-network version 6.0.0.

5.3 CVSS 3.1 Medium EPSS 0.42% · top 66.7% CWE-770 · Allocation without limits
5.3CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and prior to zebra-network version 6.0.0, several inbound deserialization paths in Zebra allocated buffers sized against generic transport or block-size ceilings before the tighter protocol or consensus limits were enforced. An unauthenticated or post-handshake peer could therefore force the node to preallocate and parse for orders of magnitude more data than the protocol intended, across headers messages, equihash solutions in block headers, Sapling spend vectors in V5/V4 transactions, and coinbase script bytes in blocks. This issue has been patched in zebrad version 4.4.0, zebra-chain version 7.0.0, and zebra-network version 6.0.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44500 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-44497Zfnd zebra-script improper verification of cryptographic signature vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, the fix for CVE-2026-41583 int…EPSS 0.30%9.3CVE-2026-41583Zfnd zebra-script vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra fai…EPSS 0.47%9.2CVE-2026-44498Zfnd zebrad vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent signature operations against …EPSS 0.38%9.2CVE-2026-41584Zfnd zebra-chain vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Orchard transactions contain a …EPSS 0.46%9.2CVE-2026-34202Zfnd zebra code injection vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerability in Zebra's transaction p…EPSS 0.93%7.2CVE-2026-40880Zfnd zebra-consensus vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic error in Zebra's transaction…EPSS 0.44%6.9CVE-2026-41585Zfnd zebra-rpc vulnerabilityZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2,…EPSS 0.43%6.3CVE-2026-40881Zfnd zebra-network allocation without limits vulnerabilityZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when deserializing addr or addrv2 mess…EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2026-44500), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.