CVE Database
/

CVE-2026-41509

Back to search

CVE-2026-41509

Published: May 8, 2026

Modified: May 8, 2026

PUBLISHED

Description

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.

VendorProductVersions

CROSS-signature

CROSS-implementation

affected
< fc6b7e78cdf789bb5c395a81dc601356f1383da0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now