CVE-2026-35679

Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.

Scoring

Severity
LOW
CVSS base score
3.5
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
EPSS probability
0.22%
CWE
CWE-358
Published
2026-04-05
Last modified
2026-04-06

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs