216.73.217.22

CVE-2026-42996

· Published 01/05/2026 07:15 · Modified 01/05/2026 15:37

Labels: CVE-2026-42996 2026-05-01CVE-2026-42996CWE-121[email protected]

Essential information

Published
01/05/2026 07:15
Modified
01/05/2026 15:37
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APRSISClient.cpp.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
js8call / js8call cpe:2.3:a:js8call:js8call:*:*:*:*:*:*:*:*
js8call / js8call improved cpe:2.3:a:js8call:js8call_improved:<3.0:*:*:*:*:*:*:*

References