Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-35679

Quick assessment

Affected
Zcash zcashd
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Zcash是一款去中心化的开源数据货币。 Zcash 6.12.0之前版本存在安全特征问题漏洞,该漏洞源于在某些条件下接受无效交易,可能导致Sprout池中的用户资金被耗尽。

CVSS 3.5 · Low EPSS 0.25% · P15

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-35679

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
不恰当实现的标准安全检查
Source: CVE Program / CVE List V5
Vulnerability Title
Zcash 安全特征问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Zcash是一款去中心化的开源数据货币。 Zcash 6.12.0之前版本存在安全特征问题漏洞,该漏洞源于在某些条件下接受无效交易,可能导致Sprout池中的用户资金被耗尽。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Zcash zcashd 0 ~ 6.12.0 -

II. Public POCs for CVE-2026-35679

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-35679

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-35679 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-35679

No comments yet


Leave a comment