CVE-2026-41509: Cross-Crypto Cross-Implementation
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7.
Affected products
- Cross-Crypto Cross-Implementation: before 2026-03-23 (fixed in 2026-03-23)
Published 2026-05-08. Last modified 2026-06-17.