Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35679.json",
"cna_assigner": "mitre",
"cwe_ids": [
"CWE-358"
]
}"2026-08-12T16:23:53Z"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"87248926002241845556570946455546873255",
"258701092093048695969126528825985120533",
"265389293760092735918030783210629178644"
]
},
"signature_type": "Line",
"source": "https://github.com/zcash/zcash/commit/db969c63f48f0f9fc518112ed0b7ace1af78b9d0",
"id": "CVE-2026-35679-3a5e1314",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/proof_verifier.h"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"82298847694456736101251213036848152989",
"177285432743515603352409056646468766578",
"323789917180549345424935058080969893080"
]
},
"signature_type": "Line",
"source": "https://github.com/zcash/zcash/commit/db969c63f48f0f9fc518112ed0b7ace1af78b9d0",
"id": "CVE-2026-35679-7ca65342",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/proof_verifier.cpp"
}
},
{
"digest": {
"function_hash": "121986004063003764855957997294863454118",
"length": 1884.0
},
"signature_type": "Function",
"source": "https://github.com/zcash/zcash/commit/db969c63f48f0f9fc518112ed0b7ace1af78b9d0",
"id": "CVE-2026-35679-979f13f8",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/main.cpp",
"function": "CheckBlock"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144145513286789480225078056171014348860",
"89164311993405282419898395416224073471",
"213182386595334963555768098276918323404",
"199273736317704137326678339016916011509",
"303702690383940087708393917548616578000",
"281171392838971751391725905404322475876",
"190677825689051677190112536842389734874"
]
},
"signature_type": "Line",
"source": "https://github.com/zcash/zcash/commit/db969c63f48f0f9fc518112ed0b7ace1af78b9d0",
"id": "CVE-2026-35679-ac44ac71",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/main.cpp"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35679.json"