Signum Node: Integer overflow in SMART_FEES fee distribution allows arbitrary miner reward inflation
Published Sep 3, 2026
7.5
HIGHCVSS 3.1
EPSS 0.33%
Description
Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbitrarily inflated block reward by crafting a block with a negative totalFeeCashBackNqt value. The vulnerability was introduced when the SMART_FEES hardfork (block ~1,029,000) enabled fee cash-back and burn accounting without overflow protection. This issue has been patched in version 3.9.9.
Affected products
-
Affected
- < 3.9.9
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Signum-Network | Signum-Node | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70527 Advisory
- https://github.com/signum-network/signum-node/releases/tag/v3.9.9 x_refsource_MISC
- https://github.com/signum-network/signum-node/security/advisories/GHSA-4vjp-2m22-r2q9 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70527 | Advisory | |
| https://github.com/signum-network/signum-node/releases/tag/v3.9.9 | x_refsource_MISC | |
| https://github.com/signum-network/signum-node/security/advisories/GHSA-4vjp-2m22-r2q9 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data