Integer Overflow Vulnerability in Signum Node Cryptocurrency Software
CVE-2026-48486

7.5HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-48486?

An integer overflow vulnerability exists in the Signum Node cryptocurrency software prior to version 3.9.9, specifically in the BlockServiceImpl.applyBlock() function. This issue allows a malicious miner to craft a block with a negative totalFeeCashBackNqt value, resulting in an arbitrarily inflated block reward. The vulnerability was introduced when the SMART_FEES hard fork enabled cash-back and burn accounting without implementing overflow protection, posing significant risks to the integrity of the mining process. This flaw has been addressed with the release of version 3.9.9.

Affected Version(s)

signum-node < 3.9.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.