CVE-2026-35679
Last modified
CVE-2026-35679 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-35679?
How severe is CVE-2026-35679?
How do I fix CVE-2026-35679?
Are you affected by CVE-2026-35679?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
