3.5
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Description
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
Basic Information
ID
CVE-2026-35679
Source
mitre
Published
Apr 5, 2026 at 21:26
Modified
Apr 6, 2026 at 14:04
Affected Product
Vendor
Zcash
Product
zcashd
Affected Versions
Zcash zcashd 0