CVE-2026-41509

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cross-crypto:cross-implementation:*:*:*:*:*:*:*:*

History

12 May 2026, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:cross-crypto:cross-implementation:*:*:*:*:*:*:*:*
References () https://github.com/CROSS-signature/CROSS-implementation/commit/fc6b7e78cdf789bb5c395a81dc601356f1383da0 - () https://github.com/CROSS-signature/CROSS-implementation/commit/fc6b7e78cdf789bb5c395a81dc601356f1383da0 - Patch
References () https://github.com/CROSS-signature/CROSS-implementation/security/advisories/GHSA-w72c-hgx8-p7cv - () https://github.com/CROSS-signature/CROSS-implementation/security/advisories/GHSA-w72c-hgx8-p7cv - Vendor Advisory
First Time Cross-crypto
Cross-crypto cross-implementation

08 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-08 14:16

Updated : 2026-05-12 14:15


NVD link : CVE-2026-41509

Mitre link : CVE-2026-41509

CVE.ORG link : CVE-2026-41509


JSON object : View

Products Affected

cross-crypto

  • cross-implementation
CWE
CWE-121

Stack-based Buffer Overflow

CWE-122

Heap-based Buffer Overflow