5
CVSSv2

CVE-2019-11636

Published: 01/05/2019 Updated: 09/05/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

z.cash zcash 2.0.5

z.cash zcash

Github Repositories

Sapling Woodchipper Website

Sapling Woodchipper Zcash Protocol-Level Denial-of-Service (CVE-2019-11636) The Sapling Woodchipper is a protocol-level Denial-of-Service against any cryptocoin which implements the Zcash 2x Sapling protocol, most notably Zcash (ZEC) itself The exact severity of the DoS depends on the exact chain parameters of each coin It's currently estimated that there are many doze