VYPR

Zcash

by Z.cash

Source repositories

CVEs (5)

  • CVE-2019-11636HigMay 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.

  • CVE-2019-7167HigMar 27, 2019
    risk 0.49cvss 7.5epss 0.02

    Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, during evaluation of polynomials related to a to-be-proven statement, produced certain bypass elements. Availability of these elements allowed a cheating prover…

  • CVE-2026-35679LowApr 5, 2026
    risk 0.16cvss 3.5epss 0.00

    Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.

  • CVE-2026-54496CriJul 17, 2026
    risk 0.00cvss 9.3epss 0.00

    ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.0, the variable-base scalar multiplication gadget in halo2_gadgets/src/ecc/chip/mul/incomplete.rs used assign_advice() for the…

  • CVE-2019-16930MedSep 28, 2019
    risk 0.00cvss 5.3epss 0.02

    Zcashd in Zcash before 2.0.7-3 allows discovery of the IP address of a full node that owns a shielded address, related to mishandling of exceptions during deserialization of note plaintexts. This affects anyone who has disclosed their zaddr to a third party.