CVE-2019-7167: Z.cash Zcash
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, during evaluation of polynomials related to a to-be-proven statement, produced certain bypass elements. Availability of these elements allowed a cheating prover to bypass a consistency check, and consequently transform the proof of one statement into an ostensibly valid proof of a different statement, thereby breaking the soundness of the proof system. This misled the original Sprout zk-SNARK verifier into accepting the correctness of a transaction.
Affected products
- Z.cash Zcash: up to and including 2.0.1
Published 2019-03-27. Last modified 2026-06-17.