CVE-2026-41509Disclosure(cross-crypto / cross-implementation)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cross-implementation

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
cross-implementation

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-08: 1Technical Details · 2026-05-08: 105-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-41509 CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overfl… https://www.cve.org/CVERecord?id=CVE-2026-41509

    Post summary

    The post reveals a buffer overflow vulnerability in the CROSS post-quantum signature algorithm prior to commit fc6b7e7, providing some technical detail but no PoC, exploit code, or patch information.

    0000098
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcross-cryptocross-implementation---

Explore more