Vulnerability Details CVE-2026-40323
SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof that the native verifier would reject. Version 6.1.0 fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 9.4%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-40323
-
cpe:2.3:a:succinct:sp1:6.0.0
-
cpe:2.3:a:succinct:sp1:6.0.1
-
cpe:2.3:a:succinct:sp1:6.0.2