🔐 CVE Alert

CVE-2026-40323

UNKNOWN 0.0

SP1 V6 Recursion Circuit Row-Count Binding Gap

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architecture. In versions 6.0.0 through 6.0.2, a soundness vulnerability in the SP1 V6 recursive shard verifier allows a malicious prover to construct a recursive proof from a shard proof that the native verifier would reject. Version 6.1.0 fixes the issue.

CWE CWE-345 CWE-354
Vendor succinctlabs
Product sp1
Published Apr 17, 2026
Stay Ahead of the Next One

Get instant alerts for succinctlabs sp1

Be the first to know when new unknown vulnerabilities affecting succinctlabs sp1 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

succinctlabs / sp1
>= 6.0.0, < 6.1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/succinctlabs/sp1/security/advisories/GHSA-63x8-x938-vx33 github.com: https://github.com/succinctlabs/sp1/releases/tag/v6.1.0