Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Potential Sprout Pool Funds Drainage via Accepting Invalid Transactions | |
| First Time appeared |
Zcash
Zcash zcashd |
|
| Vendors & Products |
Zcash
Zcash zcashd |
Mon, 06 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 05 Apr 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs. | |
| Weaknesses | CWE-358 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-04-05T21:26:58.622Z
Updated: 2026-04-06T14:04:35.190Z
Reserved: 2026-04-05T21:26:58.043Z
Link: CVE-2026-35679
Updated: 2026-04-06T14:04:22.508Z
Status : Awaiting Analysis
Published: 2026-04-05T22:16:01.193
Modified: 2026-04-07T13:20:35.010
Link: CVE-2026-35679
No data.