Closing the ZCG Vulnerability Bounty Program

@ZCG @artkor — following up on a Zcash-repository / zcashd report, separate from my earlier Zebra note above.

I am the reporter credited in the v6.12.3 release notes for GHSA-fqr9-fxpx-rfpf, which was remediated in zcashd v6.12.3. The advisory was published on 2026-05-08, and the report was submitted and disclosed during the ZCG Security Vulnerability Disclosure Initiative, before the program’s closure.

I understand from the earlier note that reports in the Zcash repository would be handled separately from the Zebra round once remediation is complete and public advisories can be properly coordinated.

To date, I have not received any contact, verification request, or status update regarding this report through email, GitHub, or the forum. I would just like to confirm:

1. Is GHSA-fqr9-fxpx-rfpf included in the separate Zcash-repository review process?

2. What is the appropriate administrative channel for this report, and what information do you need from me to proceed?

I am happy to provide whatever is required. Thanks for coordinating this.

1 Like