CVE-2019-11636: Z.cash Zcash

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.

Affected products

  • Z.cash Zcash: from 2.0.0, up to and including 2.0.4; version 2.0.5 only

Published 2019-05-01. Last modified 2026-06-17.