PT-2026-85078 · Unknown · Signum-Node
CVE-2026-48486
·
Published
2026-09-03
·
Updated
2026-09-03
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Signum Node versions prior to 3.9.9
Description
An integer overflow occurs in the
applyBlock() function of BlockServiceImpl. This issue allows a miner to obtain an arbitrarily inflated block reward by creating a block with a negative totalFeeCashBackNqt value. The flaw was introduced during the SMART FEES hardfork, which enabled fee cash-back and burn accounting without implementing overflow protection.Recommendations
Update Signum Node to version 3.9.9.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Signum-Node