Zcash zcashd versions prior to 6.12.0 contain a vulnerability that fails to properly verify Sprout pool proofs, potentially allowing invalid transactions to be accepted and user funds to be drained from the Sprout pool. This cryptographic validation flaw represents a fundamental integrity issue in the cryptocurrency's transaction verification mechanism. The vulnerability has a CVSS score of 3.5 (LOW) with a network-based attack vector, high attack complexity, and low privileges required. The impact is limited to integrity, with no confidentiality or availability concerns noted. While the EPSS score of 0.0009 indicates minimal prevalence across all CVEs, the financial implications specific to cryptocurrency applications warrant attention from affected users and operators. There is no evidence of active exploitation, and the vulnerability is not listed in the Known Exploited Vulnerabilities catalog. Community attention appears limited, with low baseline risk scores. Organizations running Zcash should prioritize upgrading to version 6.12.0 or later to remediate this proof verification deficiency, particularly those with significant Sprout pool holdings.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zcash | Zcashd | >= 0, < 6.12.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.