PT-2026-85078 · Unknown · Signum-Node

CVE-2026-48486

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Signum Node versions prior to 3.9.9
Description An integer overflow occurs in the applyBlock() function of BlockServiceImpl. This issue allows a miner to obtain an arbitrarily inflated block reward by creating a block with a negative totalFeeCashBackNqt value. The flaw was introduced during the SMART FEES hardfork, which enabled fee cash-back and burn accounting without implementing overflow protection.
Recommendations Update Signum Node to version 3.9.9.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48486
GHSA-4VJP-2M22-R2Q9

Affected Products

Signum-Node