CVE-2026-35679

CVE-2026-35679CVE-2026-35679

Description

Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.

Scoring

CVSS 3.5 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Last modified2026-07-24
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.