CVE-2026-35679 Details
Description
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
A vulnerability exists in Zcash zcashd versions prior to 6.12.0, allowing certain invalid transactions to be accepted. This issue could have potentially drained user funds from the Sprout pool, as the software sometimes failed to properly verify Sprout proofs. The vulnerability arose because of a flaw in the transaction verification logic, particularly when new blocks were added to the blockchain.
Users can upgrade to Zcash zcashd version 6.12.0, which includes the necessary fix for the Sprout transaction verification issue. Instructions for downloading this release are available on the Zcash GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 5, 2026CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zcash/zcash/commit/db969c63f48f0f9fc518112ed0b7ace1af78b9d0 | [email protected] | Source CodeVendor |
| https://github.com/zcash/zcash/releases/tag/v6.12.0 | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-358 | Improperly Implemented Security Check for Standard | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Zcash zcashd | < 6.12.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 5, 2026 | New CVE Received | [email protected] |
Volerion