CVE-2026-41509
Integer underflow in crypto_sign_open() leads to buffer overflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.
| CWE | CWE-121 CWE-122 |
| Vendor | cross-signature |
| Product | cross-implementation |
| Published | May 8, 2026 |
| Last Updated | May 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for cross-signature cross-implementation
Be the first to know when new unknown vulnerabilities affecting cross-signature cross-implementation are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CROSS-signature / CROSS-implementation
< fc6b7e78cdf789bb5c395a81dc601356f1383da0