CVE-2026-40323 is a soundness vulnerability in SP1 versions 6.0.0 through 6.0.2, a zero-knowledge virtual machine used to prove correct execution of RISC-V compiled programs. The flaw exists in the V6 recursive shard verifier, enabling malicious provers to construct recursive proofs that bypass native verification. The vulnerability has been remediated in version 6.1.0. The attack requires an attacker with prover capabilities to exploit the vulnerability, suggesting moderate complexity. The impact is significant from a cryptographic integrity perspective, as successful exploitation would undermine the soundness guarantee of zero-knowledge proofs, potentially allowing invalid computations to be fraudulently validated. The vulnerability is not currently being actively exploited in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and inactive status on threat lists. The extremely low EPSS score of 0.00013 reflects minimal current exploitation risk, though the FAUCET Risk Score of 42.0 suggests continued relevance for organizations relying on SP1 for proof generation. Organizations using affected versions should prioritize upgrading to version 6.1.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, < 6.1.0CPE matchmatch criteria | cpe:2.3:a:succinct:sp1:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.