CVE-2026-40323
SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof that the native verifier would reject. Version 6.1.0 fixes the issue.
Published:Apr 17, 2026
Last Modified:May 13, 2026
EPS:Apr 17, 2026
EPSS Score:0.00013
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Succinct
Product
Sp1
Succinct
Sp1
Vendor
Succinctlabs
Product
Sp1
Succinctlabs
Sp1
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
