CVE-2026-52735Patch

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-03: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 107-03
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Zebra (Zcash) Consensus Divergence via P2SH Sigop Undercount (CVE-2026-52735) Zebra's P2SH sigop counter uses a pure-Rust path (zcash_script) whose parser treats disabled opcodes like OP_CODESEPARATOR as an error and short-circuits via try_fold, returning zero for any sigops after the disabled opcode. zcashd counts through disabled opcodes in static analysis, so the two implementations disagree on the block-wide MAX_BLOCK_SIGOPS = 20,000 limit. An attacker with no mining power or privileges - just transaction fees - can broadcast transactions spending P2SH outputs with malicious redeem scripts. When a Zebra miner includes them in a block, Zebra validators accept it while zcashd rejects it with bad-blk-sigops, splitting the network into diverging chains with no config-level workaround. 👉Upgrade zebrad to the patched release (4.5.0 / zebra-script 7.0.0).

    Post summary

    The post highlights a critical consensus divergence flaw in Zcash’s P2SH sigop counter and advises users to upgrade to the patched zebrad release.

    00000113
    236 followersView on X

Explore more