CVE-2026-35679Disclosure

LOWCVSS 3.5 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-358

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-05: 2Technical Details · 2026-04-05: 204-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35679 Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds fr… https://www.cve.org/CVERecord?id=CVE-2026-35679

    Post summary

    The post describes a CVE that allows Zcash nodes to accept invalid transactions, which could lead to user fund loss; it provides vulnerability details but no PoC, patch, or exploitation evidence.

    00010372
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35679 Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds fr… https://www.cve.org/CVERecord?id=CVE-2026-35679 ----- Traducción: CVE-2026-35679 Zca… http://infoflow.cloud`

    Post summary

    A tweet links to CVE-2026-35679, noting that Zcash zcashd before 6.12.0 can accept invalid transactions, potentially draining funds, but provides no exploit or patch details.

    0000060
    63 followersView on X

Explore more