Vulnerabilities (CVE)

Filtered by vendor Cross-crypto Subscribe
Filtered by product Cross-implementation
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-41509 1 Cross-crypto 1 Cross-implementation 2026-05-12 N/A 9.8 CRITICAL
CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.