Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35679

19
FAUCET Score

Zcash zcashd versions prior to 6.12.0 contain a vulnerability that fails to properly verify Sprout pool proofs, potentially allowing invalid transactions to be accepted and user funds to be drained from the Sprout pool. This cryptographic validation flaw represents a fundamental integrity issue in the cryptocurrency's transaction verification mechanism. The vulnerability has a CVSS score of 3.5 (LOW) with a network-based attack vector, high attack complexity, and low privileges required. The impact is limited to integrity, with no confidentiality or availability concerns noted. While the EPSS score of 0.0009 indicates minimal prevalence across all CVEs, the financial implications specific to cryptocurrency applications warrant attention from affected users and operators. There is no evidence of active exploitation, and the vulnerability is not listed in the Known Exploited Vulnerabilities catalog. Community attention appears limited, with low baseline risk scores. Organizations running Zcash should prioritize upgrading to version 6.12.0 or later to remediate this proof verification deficiency, particularly those with significant Sprout pool holdings.

Impacted Technologies

VendorProductVersion(s)CPE
ZcashZcashd
>= 0, < 6.12.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

3.5LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 4th percentile among its peer group of 1,638 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / zcash/zcash/commit/db969c63f48f0f9fc518112ed0b7ace1af78b9d0
github.com / zcash/zcash/releases/tag/v6.12.0