Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cross-crypto
Cross-crypto cross-implementation |
|
| CPEs | cpe:2.3:a:cross-crypto:cross-implementation:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cross-crypto
Cross-crypto cross-implementation |
|
| Metrics |
cvssV3_1
|
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cross-signature
Cross-signature cross-implementation |
|
| Vendors & Products |
Cross-signature
Cross-signature cross-implementation |
Fri, 08 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Prior to commit fc6b7e7, there is a buffer overflow in crypto_sign_open() caused by an underflow of the integer mlen. This issue has been patched via commit fc6b7e7. | |
| Title | Integer underflow in crypto_sign_open() leads to buffer overflow | |
| Weaknesses | CWE-121 CWE-122 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T14:15:21.680Z
Reserved: 2026-04-20T18:18:50.681Z
Link: CVE-2026-41509
Updated: 2026-05-08T14:15:17.954Z
Status : Analyzed
Published: 2026-05-08T14:16:34.287
Modified: 2026-05-12T14:15:13.230
Link: CVE-2026-41509
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:25:21Z