ZcashFoundation Vulnerabilities and Affected Products
Vulnerabilities associated with frost.
Products
Clear product- zebra10 vulnerabilities
- zebra-consensus2 vulnerabilities
- zebrad2 vulnerabilities
- frost1 vulnerability
- zebra-chain1 vulnerability
- zebra-network1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-58359MEDIUM | frost-core: refresh shares with smaller min_signers will reduce group securityZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 through 2.1.0, refresh shares with smaller min_signers will reduce security of group. The inability to change min_signers (i.e. the threshold) with the refresh share functionality (frost_core::keys::refresh module) was not made clear to users. Using a smaller value would not decrease the threshold, and attempts to sign using a smaller threshold would fail. Additionally, after ref… | CVSS6.0v4.0 | EPSS0.286% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |