JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APRSISClient.cpp.
{
"cwe_ids": [
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42996.json",
"cna_assigner": "mitre",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "JS8Call"
},
{
"fixed": "2.3.1"
}
],
"source": [
"DESCRIPTION",
"REFERENCES"
]
}
"2026-08-12T16:24:24Z"
[
{
"id": "CVE-2026-42996-250f31b0",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1085.0,
"function_hash": "310362226120168573999317246591988258414"
},
"source": "https://github.com/js8call-improved/js8call-improved/commit/a6c7a19b82bbd7c2c0c892576f84d7449e8c7088",
"target": {
"function": "APRSISClient::grid2deg",
"file": "JS8_Main/APRSISClient.cpp"
}
},
{
"id": "CVE-2026-42996-c48c8117",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"7704383707382585762460477450412960954",
"45573664063618283326767607752469245288",
"208545788373079494033583903244752096422",
"69805230127947473845792696962174410171",
"146283949885922591490952867623073401660",
"38629222466732001122922191557100741996",
"298688861202126477694900392063424875158",
"11502150389775127945672555941005320745",
"158319704011829504241306459693300239463",
"125852044605167572997560515222226829810",
"123295126120006517314484893525258049488"
]
},
"source": "https://github.com/js8call-improved/js8call-improved/commit/a6c7a19b82bbd7c2c0c892576f84d7449e8c7088",
"target": {
"file": "JS8_Main/APRSISClient.cpp"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42996.json"