Zcash is a privacy-focused cryptocurrency protocol and reference implementation, with a narrowly scoped but specialized product footprint centered on the core zcash software. Its observed vulnerability pattern centers on improper handling of exceptional and edge-case conditions, reflecting the complexity of cryptographic protocol implementation and state management in a distributed system. Current CVE counts, severity, exploitation activity, and remediation timelines are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Z.Cash over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11636HIGH Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack. | May 1, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-7167HIGH Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, during evaluation of polynomials related to a to-be-proven sta | Mar 27, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-16930MEDIUM Zcashd in Zcash before 2.0.7-3 allows discovery of the IP address of a full node that owns a shielded address, related to mishandling of exceptions during deserialization of note p | Sep 28, 2019 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Z.Cash.
Media articles that mention a CVE ID that affects a product developed by Z.Cash — matched by CVE ID, not by vendor name.