Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40323

24
FAUCET Score

CVE-2026-40323 is a soundness vulnerability in SP1 versions 6.0.0 through 6.0.2, a zero-knowledge virtual machine used to prove correct execution of RISC-V compiled programs. The flaw exists in the V6 recursive shard verifier, enabling malicious provers to construct recursive proofs that bypass native verification. The vulnerability has been remediated in version 6.1.0. The attack requires an attacker with prover capabilities to exploit the vulnerability, suggesting moderate complexity. The impact is significant from a cryptographic integrity perspective, as successful exploitation would undermine the soundness guarantee of zero-knowledge proofs, potentially allowing invalid computations to be fraudulently validated. The vulnerability is not currently being actively exploited in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and inactive status on threat lists. The extremely low EPSS score of 0.00013 reflects minimal current exploitation risk, though the FAUCET Risk Score of 42.0 suggests continued relevance for organizations relying on SP1 for proof generation. Organizations using affected versions should prioritize upgrading to version 6.1.0.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.0.0, < 6.1.0CPE matchmatch criteria
cpe:2.3:a:succinct:sp1:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.9HIGH

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
HIGH
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
9.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 1st percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

rustpatch availablevia ghsa
Product: sp1_sdkFixed in: 6.1.0
rustpatch availablevia ghsa
Product: sp1_recursion_circuitFixed in: 6.1.0
rustpatch availablevia ghsa
Product: sp1_proverFixed in: 6.1.0

Vendor Advisories (1)

rustGHSA-63x8-x938-vx33high

SP1 V6 Recursion Circuit Row-Count Binding Gap

Apr 14, 2026

References

github.com / succinctlabs/sp1/releases/tag/v6.1.0
Release Notes
github.com / succinctlabs/sp1/security/advisories/GHSA-63x8-x938-vx33
Vendor Advisory