GHSA-vjf8-9fx6-mv6xMedium▾ SunlitTriton VM Soundness Vulnerability due to Missing Constraint
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The instruction sponge_absorb_mem Triton VM fails to verify that hashed values come from the claimed memory location. Malicious provers can substitute arbitrary data instead of actual memory contents.
Any application using instruction sponge_absorb_mem to hash memory data can be given a proof for a forged hash that doesn't correspond to the actual memory. This breaks the security of memory-based commitments.
The flaw was corrected in commits 17c7ba0a and ef9d9e72 by including the appropriate constraints.
triton-vm >= 0.42.0-alpha.4, < 4.0.0Upgrade to a patched release:
triton-vm 4.0.0Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2021-0156NoneTriton VM Soundness Vulnerability due to Missing Constraint
CVE-2026-63127High· 8.2RMCP is an official Rust SDK for the Model Context Protocol
CVE-2026-54496Critical· 9.3Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness
CVE-2026-52737Medium· 5.3ZEBRA is a Zcash node written entirely in Rust
CVE-2026-92161Critical· 9.8FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers
CVE-2026-25602Low· 2.3Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server)