PT-2026-38965 · Cross · Cross

·

CVE-2026-41509

·

Published

2026-05-08

·

Updated

2026-05-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CROSS versions prior to commit fc6b7e7
Description A buffer overflow exists in the crypto sign open() function caused by an underflow of the mlen integer. This occurs within the reference and optimized implementations of the CROSS post-quantum signature algorithm.
Recommendations Update to the version containing commit fc6b7e7.

Exploit

Fix

Heap Based Buffer Overflow

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41509
GHSA-W72C-HGX8-P7CV

Affected Products

Cross