Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbitrarily inflated block reward by crafting a block with a negative totalFeeCashBackNqt value. The vulnerability was introduced when the SMART_FEES hardfork (block ~1,029,000) enabled fee cash-back and burn accounting without overflow protection. This issue has been patched in version 3.9.9.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-190"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48486.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48486.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"71344313484646680913669198488519996053",
"299094564097870482772236802660430531409",
"336241233098094065944634198307005435622",
"255825274679377710856883545420679233164"
],
"threshold": 0.9
},
"id": "CVE-2026-48486-9c4ee4b2",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/signum-network/signum-node/commit/d2597c579e22b122b03a6c24291ce85a14aa2460",
"target": {
"file": "src/brs/Signum.java"
}
}
]
"2026-09-11T09:02:40Z"