DNA View

CVE-2026-40323

Low
Low Medium High Critical
CVSS Score
Published: Apr 18, 2026
Last Modified: Apr 18, 2026

Vulnerability Description

SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof that the native verifier would reject. Version 6.1.0 fixes the issue.

Severity Details

out of 10.0
Low

Weakness Type (CWE)

CWE-345

Insufficient Verification of Data Authenticity

Description
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Typical Severity
Medium
Abstraction Level
Class

Key Information

Published Date
April 18, 2026