Integer Overflow Vulnerability in Signum Node Cryptocurrency Software
CVE-2026-48486
7.5HIGH
What is CVE-2026-48486?
An integer overflow vulnerability exists in the Signum Node cryptocurrency software prior to version 3.9.9, specifically in the BlockServiceImpl.applyBlock() function. This issue allows a malicious miner to craft a block with a negative totalFeeCashBackNqt value, resulting in an arbitrarily inflated block reward. The vulnerability was introduced when the SMART_FEES hard fork enabled cash-back and burn accounting without implementing overflow protection, posing significant risks to the integrity of the mining process. This flaw has been addressed with the release of version 3.9.9.
Affected Version(s)
signum-node < 3.9.9
