CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.
References
Configurations
History
12 May 2026, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CPE | cpe:2.3:a:cross-crypto:cross-implementation:*:*:*:*:*:*:*:* | |
| References | () https://github.com/CROSS-signature/CROSS-implementation/commit/fc6b7e78cdf789bb5c395a81dc601356f1383da0 - Patch | |
| References | () https://github.com/CROSS-signature/CROSS-implementation/security/advisories/GHSA-w72c-hgx8-p7cv - Vendor Advisory | |
| First Time |
Cross-crypto
Cross-crypto cross-implementation |
08 May 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 14:16
Updated : 2026-05-12 14:15
NVD link : CVE-2026-41509
Mitre link : CVE-2026-41509
CVE.ORG link : CVE-2026-41509
JSON object : View
Products Affected
cross-crypto
- cross-implementation
