CVE-2026-35679
Deferred
Deferred - Pending Action
Proof Verification Bypass in Zcashd Sprout Pool Risks Fund Drain
Publication date: 2026-04-05
Last updated on: 2026-05-19
Assigner: MITRE
Description
Description
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zcash | zcashd | to 6.12.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-358 | The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique. |