Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.
| Vendor | Product | Versions |
|---|---|---|
| zcash | zcashd | 0 |
Updated affected versions to 6.11.x, changed severity to MEDIUM, and noted that no exploit is available.
Initial creation