CVE-2026-42996: JS8CALL
Critical severity, CVSS 10.0. EPSS: 0.6% chance of exploitation in the next 30 days.
JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APRSISClient.cpp.
Affected products
- JS8CALL JS8CALL: up to and including 2.3.1
- JS8CALL-Improved JS8CALL-Improved: before 3.0 (fixed in 3.0)
Published 2026-05-01. Last modified 2026-06-17.