CVE-2026-41509: Cross-Crypto Cross-Implementation

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.

Affected products

  • Cross-Crypto Cross-Implementation: before 2026-03-23 (fixed in 2026-03-23)

Published 2026-05-08. Last modified 2026-06-17.