CVE-2026-35679
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
Scoring
- Severity
- LOW
- CVSS base score
- 3.5
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
- EPSS probability
- 0.22%
- CWE
- CWE-358
- Published
- 2026-04-05
- Last modified
- 2026-04-06
Affected products
- Zcash zcashd
Weakness type
Related vulnerabilities
- CVE-2026-46582 — A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
- CVE-2026-65058 — Trezor Safe improper security check in on-device display
- CVE-2026-49783 — Secure Boot Security Feature Bypass Vulnerability
- CVE-2026-54431 — Improper Data Validation in liboauth2
- CVE-2026-12577 — DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2026-42081 — free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-42082 — free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover